Credential Theft
- Mimikatz
IncRansom is a ransomware family and associated extortion operation observed in enterprise intrusions during 2025 and 2026.
Profile source: Mallory opens in a new tabIncransom
IncRansom is a ransomware family and associated extortion operation observed in enterprise intrusions during 2025 and 2026. It has been identified among active ransomware groups targeting organizations in multiple sectors, including healthcare, and has been linked to victim postings on a public leak site, indicating use of a double-extortion model in which stolen data is leveraged for coercion in addition to encryption-based disruption.
Observed ransomware intrusions involving IncRansom fit broader contemporary enterprise ransomware tradecraft. Reported cases show attackers obtaining access to corporate environments, conducting credential theft and post-compromise network operations, exfiltrating data before detonation, and then deploying ransomware across reachable systems. In enterprise incidents of this class, operators commonly abuse administrative shares and centralized management mechanisms to distribute payloads, target backup and virtualization infrastructure to inhibit recovery, and time encryption for off-hours execution. VMware and backup platforms are frequently prioritized in such attacks because disabling recovery options increases extortion pressure.
IncRansom has been observed affecting organizations in healthcare-related contexts and appears in reporting alongside other major ransomware families active in the same period, including Akira, LockBit, Fog, and Lynx. Available information supports classifying IncRansom as a ransomware threat used for data theft and extortion against enterprise victims, but does not provide high-confidence, family-specific technical details beyond its role in ransomware incidents and leak-site-based victim shaming.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.