INC the ransomware band that is redefining 2026

Author: Published 4 min de lectura 157 reading

The images in this article were generated with artificial intelligence. How we publish

In less than three years INC has gone from an incipient operation of ransomware- as- a- service to one of the most prolific bands in the first half of 2026, with figures that speak for themselves: approximately: 830 victims since August 2023 and more than 65% of attacks on organizations in the United States. This expansion is not a coincidence but the result of a reconfigured criminal ecosystem: when actors such as LockBit and BlackCat were weakened, affiliates and services migrated to alternatives such as INC, they offered operational continuity and greater availability of "criminal product."

A remarkable technical feature of INC is the rewriting of its encryption for Windows and Linux / ESXi in Rust, a modern language that facilitates multiplatform deployments and complicates forensic analysis for its ability to produce more difficult binaries to disassemble. In addition to this, the marketing of variants in clandestine forums has generated families from important code overlap, thus expanding the risk area for organizations that believe that a brand change reduces the threat.

INC the ransomware band that is redefining 2026
Image generated with IA.

The chain of attack reported by analysts combines well-known and highly effective techniques: taking advantage of vulnerabilities in perimetral devices and public services, buying credentials, speed-phishing, using LOLBins for side movement and operating backup by an updated dumper capable of extracting credentials from modern Veeam implementations using DPAPI with salt. The attack vector is not sophisticated in the sense of using unpublished tricks, but it is effective and scalable: the repetition of proven tactics is creating a constant flow of incidents.

Specific techniques to be monitored include the use of manipulated drivers to deactivate defenses (known as BYOVD), the deployment of commercial remote management tools such as AnyDesk or ScreenConnect for human control and the exfiltration of data by Rclone after packing them with passwords. The ciphers also allow controls from command line - including an argument "--esxi" to turn off virtual machines - and accelerate the process with multi-thread and partial encryption, reducing the defensive response window.

The pattern that leaves INC highlights a strategic lesson: it is not necessary to develop cryptic news to cause mass damage; the combination of reusable code, sale in clandestine markets, affiliates motivated by rapid and objective profits with high operational urgency (health, legal services, manufacturing, construction) is sufficient to amplify the impact. The consequences go beyond the direct objective: when sectors dependent on continuous operations are interrupted, risks to suppliers and supply chains are increased.

For cybersecurity organizations and teams, the practical priorities are clear. First, protect and isolate backups; copying strategies should include immutable repositories, back-up network segmentation and regular restability verification. Secondly, prioritise the patching of publicly exposed edge devices and applications, as well as strengthen the implementation of Veeam and other backup products to minimize the possibility of the removal of credentials. In addition, it is critical to restrict the use of administrative tools and LOLBins, apply minimum privilege principles and deploy detection controls that identify RDP, PsExec, Rclone and remote management connectivity abuse patterns.

INC the ransomware band that is redefining 2026
Image generated with IA.

Early detection requires observability and response capabilities: EDR / NGAV with extended telemetry, specific rules for common chains (including indicators associated with suspicious drivers and recombinated binaries in Rust), abnormal behavior detection on backup servers and alerts on unusual arguments in critical processes. Organizations should also practice incident response exercises, coordinate communication with suppliers and partners, and maintain open channels with threat intelligence authorities and services to share indicators and tactics.

Finally, operational risk management requires policies that combine technical controls, legal preparation and financial planning. Cyber insurance does not replace basic hygiene; instead, investment in network segregation, multifactor authentication, rotation and protection of secrets, and regular restoration tests reduce the probability of payments and accelerate recovery. The threat posed by INC shows that corporate resilience depends more on sustainable and repeatable measures than on miracle solutions.

To deepen best practices and Ransomware defence frameworks, teams can consult official resources such as the CISA guide on how to prevent and respond to Ransomware in companies https: / / www.cisa.gov / stopransomware and the MITRE ATT & CK project's threat tactics and techniques repository https: / / attack.mitre.org / which help map observed indicators to specific defensive controls.

Coverage

Related

More news on the same subject.