INC Ransomware: Rust-Based RaaS Exploiting Public-Facing Edge Devices

Red | Attack
Download Now
INC Ransomware: Rust-Based RaaS Exploiting Public-Facing Edge Devices | HivePro Threat Advisory TA2026203
Threat Advisory • Attack Report

INC Ransomware: Rust-Based RaaS Exploiting Public-Facing Edge Devices

A Rust-based ransomware-as-a-service operation, also tracked as GOLD IONIC, INC ransomware exploits unpatched public-facing edge appliances and broker-supplied credentials to compromise Windows, Linux, and VMware ESXi environments, then applies double-extortion pressure through data theft, encryption, and public shaming.

TA2026203 Admiralty Code A1 Ransomware Ransomware-as-a-Service Double Extortion Patch Available
Date of Publication
July 17, 2026
TA Number
TA2026203
Admiralty Code
A1
First Seen
July 2023
Malware
INC ransomware (aka GOLD IONIC, G1032)
Targeted Regions
Global (except CIS countries)
Targeted Platforms
Windows, Linux, VMware ESXi
Targeted Industries
Legal, Manufacturing, Healthcare, Technology, Construction & more
Victims Claimed
800+ since 2023

Summary

INC ransomware is a Rust-based ransomware-as-a-service operation, also known as GOLD IONIC, that has claimed more than 800 victims since first emerging in July 2023 and now ranks among 2026's most active ransomware groups. The operation predominantly strikes legal, manufacturing, healthcare, technology, and construction organizations, with the United States as the primary target.

INC ransomware operators gain initial access through unpatched, public-facing edge appliances, notably exploiting CVE-2023-3519 and CVE-2023-48788, or through broker-supplied stolen credentials. Once inside, the affiliates rely on living-off-the-land binaries and a modified Veeam credential dumper to move laterally across Windows, Linux, and VMware ESXi infrastructure.

Before encryption, data is exfiltrated to attacker-controlled cloud storage, and the operation applies aggressive defense impairment through driver-dropping process killers and shadow-copy deletion. Victims face pressure from multiple directions: a Tor negotiation portal, a public leak site, wallpaper defacement, and ransom notes printed directly to networked printers, reinforcing INC ransomware's double-extortion model.

First Seen: July 2023  |  Targeted Regions: Global, except CIS countries  |  Targeted Platforms: Windows, Linux, VMware ESXi

Targeted Industries: Manufacturing, Legal, Healthcare, Business Services & Consulting, Financial Services, Retail, Charitable Organizations, Government, Transportation, Technology, Education, Real Estate, Agriculture, Pharmaceutical, Energy, Telecommunications, Associations, Media, Aerospace, Defense, Insurance, Religion, Hospitality, Aviation, Food Service


Attack Details

#1 Origins and Rise of INC Ransom

INC Ransom is a Ransomware-as-a-Service (RaaS) operation that emerged in July 2023, also tracked under the alias GOLD IONIC. It established itself as a semi-private, affiliate-based operation rather than a rebrand, and by 2026 matured into a top-tier operator, with more than 800 victims claimed since 2023. Its rise was opportunistic: the disruption of LockBit and the shutdown of BlackCat pushed affiliates and tooling toward INC ransomware.

#2 Ecosystem Influence and Victimology

The group's ecosystem influence is distinctive. In May 2024 the INC ransomware source code was listed on underground forums for $300,000; shortly after, the Lynx operation emerged with substantial code overlap, and Sinobi later appeared. The original brand continues to operate while its codebase propagates into adjacent ransomware families. Victimology is US-centric: the United States accounts for 60% of victims, with a long tail led by Australia, Canada, and Germany, and a complete absence of CIS-region victims, suggesting CIS-based operators. The 2026 top five targeted sectors are legal services, manufacturing, technology, healthcare, and construction, a shift away from the group's earlier education focus.

#3 Attack Chain and Toolkit

The attack chain favors known techniques. Initial access comes via spear-phishing, initial access broker (IAB) credentials, and public-facing exploits: CVE-2023-3519 (Citrix NetScaler), CVE-2023-48788 (Fortinet FortiClient EMS), CVE-2024-57727 (SimpleHelp), and CVE-2025-5777 (Citrix Bleed 2). A modified Veeam credential dumper upgraded for salted-DPAPI, RDP/PsExec lateral movement, a BYOVD (Bring Your Own Vulnerable Driver) process terminator that drops vulnerable drivers, remote-access tooling for command-and-control, and 7-Zip plus rclone exfiltration round out the INC ransomware toolkit.

#4 Rust-Based Payloads and Extortion Model

Both INC ransomware payloads are now Rust-based. The Windows encryptor deletes shadow copies, uses a hybrid Salsa20/AES scheme with Curve25519 ECC, and appends a .INC extension to encrypted files. The Linux/ESXi variant supports --esxi (VM shutdown via vim-cmd), --motd, --daemon, and fast/medium/slow encryption modes, deriving per-file AES-128-CTR keys via X25519 ECDH. Extortion is double-sided: a credentialed negotiation site plus a public leak site, combined with wallpaper hijacking, INC-README ransom notes, and automated network printing of ransom notes.

Exploited Vulnerabilities
CVE Name Affected Product
CVE-2023-3519 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability Citrix NetScaler ADC and NetScaler Gateway
CVE-2023-48788 Fortinet FortiClient EMS SQL Injection Vulnerability Fortinet FortiClient EMS
CVE-2024-57727 SimpleHelp Path Traversal Vulnerability SimpleHelp Remote Support Software
CVE-2025-5777 CitrixBleed 2 (Citrix NetScaler Gateway Out-of-Bounds Read Vulnerability) Citrix NetScaler ADC and NetScaler Gateway

Recommendations

01

Patch Exploited Edge Appliances

Prioritize remediation of the internet-facing vulnerabilities tied to INC ransomware intrusions, CVE-2023-3519 (Citrix NetScaler ADC/Gateway), CVE-2023-48788 (Fortinet FortiClient EMS), CVE-2024-57727 (SimpleHelp RMM), and CVE-2025-5777 (Citrix Bleed 2), and maintain a vulnerability management program that fast-tracks fixes for flaws known to be exploited by ransomware operators.

02

Harden and Monitor Remote Access

Restrict RDP and SSH exposure from the internet, harden and monitor external remote services, and enforce multifactor authentication on all remote and privileged access points to blunt the value of broker-supplied and stolen credentials.

03

Protect Veeam and Backup Infrastructure

Isolate backup servers, apply least-privilege service accounts, and monitor for base64-encoded PowerShell execution and unauthorized SQL queries against Veeam credential stores that indicate use of the modified Veeam-Get-Creds credential dumper.

04

Enforce Strong Identity Controls

Require complex, regularly rotated alphanumeric passwords, watch for the creation of new privileged accounts, and alert on off-hours authentication and anomalous administrative activity.

05

Maintain Offline, Immutable Backups

Follow the 3-2-1 backup rule with at least one offline or immutable copy stored off-site under separate credentials, and routinely test restoration to ensure recovery without paying a ransom.

06

Deploy Anti-Tamper EDR

Run endpoint detection and response with behavioral detection and anti-tamper protections enabled, and monitor for driver-based process termination (including the vulnerable drivers filwfp.sys, filnk.sys, and fildds.sys), Volume Shadow Copy deletion, and safe-mode boot manipulation.

07

Monitor Living-off-the-Land and RMM Tooling

Alert on suspicious use of PsExec, WMIC, net, and network scanners such as Advanced IP Scanner and netscan, and inventory or restrict unsanctioned remote management tools including AnyDesk, ScreenConnect, and TeamViewer.

08

Detect Staging and Exfiltration

Watch for 7-Zip archiving of large data sets and outbound transfers via rclone or MegaSync to cloud storage such as Mega.nz, and block or closely monitor access to unsanctioned file-sharing services.


Indicators of Compromise (IOCs)

SHA256 Hashes

31800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502
ea721240c14e3d14f8d88e0020880448c6c602f1180a1e5dbe40871cfeedcc22
8d1a22c430252f29611766b8e4a82af0fba60d609246463466b384d6d4793df4
bf8c45e5aa9551a17eefbd1d179422c32b4309c47ee9a3f315bb80ed6d4f7efc
6bf155b269d452f3c3b62832b27bbebe4da436e228dbf521155b1d5989e3743f
1898d056463284d849801cbdea6a3dec6c9f568f01569912c3868a5eea9a5449
24f6c0ca39b2a5593086ff56d818ddfbde121f8e44d54faa762e510397dc9db7
dc9938f51150d13a69fc25f3f19052eacb1bf0a086fd5cf39762501fb3ddd7da
acce811c4fc2a6e3fddd4231e386f1648ca44f039d2d275316bc0a0fc96e0af4
90e46e89fec2108a1cb4850bb33e3563e92a14d04e1e613ac8c9311f152d294c
ff5da8f0330a4c581c37284c74aae2683c007dc6e406e1e2e6803e7bb398b77b
97aebda5482899fef84a24e456bff055acaa47e5ab4029f768d9e0c62a660ce2
1d10d8f5a420d0e4683b4cb40bcf0c984d1e7ea1f3b4442a00a525584632ac11
f6a01d0246ce31faf6938ea488086d4358505405a4ef5c5faa482e79e92cb347
d65120291dee76c694f8bea54841f7f68329b499b28f4aee5ea5c9369a7432cb
765508aa2ec6a1b73a76a23f4fa559d32355622748c91a46ed7b315eae2ee60a
d26bfb0147f60dc6500a9298d521ee67b49daaf4b8f8be54e7cc8fd86a597570
589d9480fbfec2d8e61638eb0b537183d0f9977411fd1d2c0f8eb611feebe880
7f37351979c249417cb180b4ede0ed17e5fe2a1f08add4d72606b589f8fdb245
5cc212f84d2bf3fbab165aaf09b16e00fcf2f1ccd880d24b14404c53dcdbf241
60aeb9f7bccf377ff02ed64783e66a62c0f976878d9729b067bc7e5b0b9da9d6
6cd349eda0fa6c8b274a0920852c68f8b727afea1fdbc69ad183cef05d9cf141

Domains

incblog[.]su
incbackend[.]top
incapt[.]blog

TOR Addresses

incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad[.]onion
incpaykabjqc2mtdxq6c23nqh4x6m5dkps5fr6vgdkgzp5njssx6qkid[.]onion
incblog7vmuq7rktic73r4ha4j757m3ptym37tyvifzp2roedyyzzxid[.]onion
incbackrlasjesgpfu5brktfjknbqoahe2hhmqfhasc5fb56mtukn4yd[.]onion
incbacg6bfwtrlzwdbqc55gsfl763s3twdtwhp27dzuik6s6rwdcityd[.]onion

Filenames

INC-README.txt, INC-README.html, ipscan.exe, Advanced_IP_Scanner_2.5.3850.exe, netscan.exe, pskill.exe, ProcessTerminator.exe, filwfp.sys, filnk.sys, fildds.sys, Veeam-Get-Creds.ps1

File Paths

C:\Program Files\Angry IP Scanner\ipscan.exe
C:\ProgramData\VMware\libsm2\netscan.exe


Potential MITRE ATT&CK TTPs

T1190
Initial Access
Exploit Public-Facing Application
T1566.001
Initial Access
Phishing: Spearphishing Attachment
T1078
Initial Access
Valid Accounts
T1059.001
Execution
Command and Scripting Interpreter: PowerShell
T1059.003
Execution
Command and Scripting Interpreter: Windows Command Shell
T1543.003
Persistence
Create or Modify System Process: Windows Service
T1136
Persistence
Create Account
T1078
Privilege Escalation
Valid Accounts
T1562.001
Defense Evasion
Impair Defenses: Disable or Modify Tools
T1562.009
Defense Evasion
Impair Defenses: Safe Boot Mode
T1070
Defense Evasion
Indicator Removal
T1003
Credential Access
OS Credential Dumping
T1046
Discovery
Network Service Scanning
T1057
Discovery
Process Discovery
T1087
Discovery
Account Discovery
T1021.001
Lateral Movement
Remote Services: Remote Desktop Protocol
T1021.002
Lateral Movement
Remote Services: SMB/Windows Admin Shares
T1219
Command and Control
Remote Access Software
T1560.001
Collection
Archive Collected Data: Archive via Utility
T1567.002
Exfiltration
Exfiltration Over Web Service: Exfiltration to Cloud Storage
T1486
Impact
Data Encrypted for Impact
T1490
Impact
Inhibit System Recovery
T1491.001
Impact
Defacement: Internal Defacement
T1529
Impact
System Shutdown/Reboot

References & Patch Links

Patch Links
Recent Breaches
References