Skip to content

Incransom

IncRansom is a ransomware family and associated extortion operation observed in enterprise intrusions during 2025 and 2026.

Profile source: Mallory opens in a new tab

Incransom

Family profile

IncRansom is a ransomware family and associated extortion operation observed in enterprise intrusions during 2025 and 2026. It has been identified among active ransomware groups targeting organizations in multiple sectors, including healthcare, and has been linked to victim postings on a public leak site, indicating use of a double-extortion model in which stolen data is leveraged for coercion in addition to encryption-based disruption.

Observed ransomware intrusions involving IncRansom fit broader contemporary enterprise ransomware tradecraft. Reported cases show attackers obtaining access to corporate environments, conducting credential theft and post-compromise network operations, exfiltrating data before detonation, and then deploying ransomware across reachable systems. In enterprise incidents of this class, operators commonly abuse administrative shares and centralized management mechanisms to distribute payloads, target backup and virtualization infrastructure to inhibit recovery, and time encryption for off-hours execution. VMware and backup platforms are frequently prioritized in such attacks because disabling recovery options increases extortion pressure.

IncRansom has been observed affecting organizations in healthcare-related contexts and appears in reporting alongside other major ransomware families active in the same period, including Akira, LockBit, Fog, and Lynx. Available information supports classifying IncRansom as a ransomware threat used for data theft and extortion against enterprise victims, but does not provide high-confidence, family-specific technical details beyond its role in ransomware incidents and leak-site-based victim shaming.

Capabilities

  • Exfiltration
  • Extortion

Operational record

1
YARA rules
7
Leak sites
2 available

Credential Theft

  • Mimikatz

Discovery Enum

  • AdFind
  • Advanced IP Scanner
  • SoftPerfect NetScan

Exfiltration

  • 7-Zip
  • BackBlaze
  • MEGA
  • RClone
  • Restic
  • WinRAR
  • s5cmd

LOLBAS

  • Finger
  • PsExec

Networking

  • Bitvise SSH Client

RMM Tools

  • AnyDesk

Recent claims

MITRE ATT&CK

Incransom in ATT&CK

27 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.