The images in this article were generated with artificial intelligence. How we publish
In less than three years INC has gone from an incipient operation of ransomware- as- a- service to one of the most prolific bands in the first half of 2026, with figures that speak for themselves: approximately: 830 victims since August 2023 and more than 65% of attacks on organizations in the United States. This expansion is not a coincidence but the result of a reconfigured criminal ecosystem: when actors such as LockBit and BlackCat were weakened, affiliates and services migrated to alternatives such as INC, they offered operational continuity and greater availability of "criminal product."
A remarkable technical feature of INC is the rewriting of its encryption for Windows and Linux / ESXi in Rust, a modern language that facilitates multiplatform deployments and complicates forensic analysis for its ability to produce more difficult binaries to disassemble. In addition to this, the marketing of variants in clandestine forums has generated families from important code overlap, thus expanding the risk area for organizations that believe that a brand change reduces the threat.

The chain of attack reported by analysts combines well-known and highly effective techniques: taking advantage of vulnerabilities in perimetral devices and public services, buying credentials, speed-phishing, using LOLBins for side movement and operating backup by an updated dumper capable of extracting credentials from modern Veeam implementations using DPAPI with salt. The attack vector is not sophisticated in the sense of using unpublished tricks, but it is effective and scalable: the repetition of proven tactics is creating a constant flow of incidents.
Specific techniques to be monitored include the use of manipulated drivers to deactivate defenses (known as BYOVD), the deployment of commercial remote management tools such as AnyDesk or ScreenConnect for human control and the exfiltration of data by Rclone after packing them with passwords. The ciphers also allow controls from command line - including an argument "--esxi" to turn off virtual machines - and accelerate the process with multi-thread and partial encryption, reducing the defensive response window.
The pattern that leaves INC highlights a strategic lesson: it is not necessary to develop cryptic news to cause mass damage; the combination of reusable code, sale in clandestine markets, affiliates motivated by rapid and objective profits with high operational urgency (health, legal services, manufacturing, construction) is sufficient to amplify the impact. The consequences go beyond the direct objective: when sectors dependent on continuous operations are interrupted, risks to suppliers and supply chains are increased.
For cybersecurity organizations and teams, the practical priorities are clear. First, protect and isolate backups; copying strategies should include immutable repositories, back-up network segmentation and regular restability verification. Secondly, prioritise the patching of publicly exposed edge devices and applications, as well as strengthen the implementation of Veeam and other backup products to minimize the possibility of the removal of credentials. In addition, it is critical to restrict the use of administrative tools and LOLBins, apply minimum privilege principles and deploy detection controls that identify RDP, PsExec, Rclone and remote management connectivity abuse patterns.

Early detection requires observability and response capabilities: EDR / NGAV with extended telemetry, specific rules for common chains (including indicators associated with suspicious drivers and recombinated binaries in Rust), abnormal behavior detection on backup servers and alerts on unusual arguments in critical processes. Organizations should also practice incident response exercises, coordinate communication with suppliers and partners, and maintain open channels with threat intelligence authorities and services to share indicators and tactics.
Finally, operational risk management requires policies that combine technical controls, legal preparation and financial planning. Cyber insurance does not replace basic hygiene; instead, investment in network segregation, multifactor authentication, rotation and protection of secrets, and regular restoration tests reduce the probability of payments and accelerate recovery. The threat posed by INC shows that corporate resilience depends more on sustainable and repeatable measures than on miracle solutions.
To deepen best practices and Ransomware defence frameworks, teams can consult official resources such as the CISA guide on how to prevent and respond to Ransomware in companies https: / / www.cisa.gov / stopransomware and the MITRE ATT & CK project's threat tactics and techniques repository https: / / attack.mitre.org / which help map observed indicators to specific defensive controls.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...

Npm campaign installs RedC2 4.0 when importing malicious packages
Cybersecurity researchers have found a malicious package campaign in the npm ecosystem that, at first sight, provide calendar and calculation utilities but actually serve as a v...