🇷🇺 INC Ransom¶
Threat-actor battle card · maintained from public sources · last updated 2026-08-09 · also known as GOLD IONIC, IncRansom, Inc. Ransom
Overview¶
INC Ransom (also known as GOLD IONIC) is a ransomware-as-a-service (RaaS) group that emerged in August 2023 and has grown into one of the most prolific ransomware operations in 2026, claiming over 885 victims since launch (as of August 2, 2026; up from 830+ reported in June 2026). US organizations account for over 65% of victims. Top targeted sectors: legal services, manufacturing, healthcare, technology, and construction. The group runs a structured affiliate programme and has attracted experienced operators from disrupted ransomware operations. No publicly confirmed operator identities; cybersecurity researchers attribute Russian-speaking criminal involvement.
Tradecraft¶
- Initial access: Spear-phishing, IAB-purchased credentials, and exploitation of public-facing application vulnerabilities — notably CVE-2023-3519 (Citrix NetScaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM), CVE-2025-5777 (Citrix NetScaler Bleed 2), CVE-2026-24858 (FortiCloud SSO SAML assertion bypass, CVSS 9.8; mass exploitation began June 2026 — see FortiBleed below), CVE-2026-15409 (SonicWall SMA 1000, CVSS 10.0 — unauthenticated WebSocket tunnel to restricted services) chained with CVE-2026-15410 (SonicWall SMA 1000, CVSS 7.2 — root privilege escalation) for full RCE/takeover; pre-disclosure exploitation by threat cluster UTA0533 confirmed from June 22, 2026; patched mid-July 2026 but exploitation continued post-patch with confirmed MFA seed theft — patching alone is insufficient, full credential/MFA reset required.
- Encryptor: Rust-based cross-platform locker (Windows and Linux/ESXi builds); complicates static analysis and enables efficient cross-platform campaigns.
- Extortion model: Double extortion — data exfiltration before encryption, threat of public DLS release.
- Printer ransom-note delivery: On successful encryption, the malware scans the compromised network for active printers and automatically prints physical copies of the ransom demand — a documented escalation tactic since 2024.
- SonicWall intrusion toolchain (2026): Post-exploitation tools deployed in the SMA 1000 chain — KNUCKLEBALL (Python launcher), Suo5 (HTTP tunnel proxy over HTTP/S), ORANGETAIL (custom Java webshell with Behinder-like capabilities) — confirm a purpose-built toolkit distinct from the general affiliate toolset.
- Backup targeting: Modified credential dumper supporting Veeam's salted DPAPI encryption (newer deployments), specifically designed to compromise backup infrastructure and eliminate recovery options.
- Hands-on-keyboard style: Uses legitimate remote-management tools for lateral movement (consistent with affiliate operating procedures from post-LockBit/RansomHub disruption pool).
- Recent surge (June 2026): Claimed attacks against 10 law firms and legal services organizations within a 48-hour window — indicates a coordinated affiliate campaign against the legal sector.
- INC Ransom = Lynx (forensic confirmation, July 2026): Independent forensic analysis and real-time operator tracking confirmed that a single operator was simultaneously logged into both an INC Ransom and a Lynx negotiation panel during active negotiations — corroborating prior code-level analysis that the two operations share infrastructure and personnel. Scale from the FortiBleed campaign: 430,000 FortiGate firewalls targeted, 354 completed intrusions, 12 ransomware deployments, approximately 20 members, 200+ operational servers, and approximately 73,000 harvested credential sets found in a publicly exposed server.
Notable victims¶
- NHS Scotland (Dumfries and Galloway) — public health/UK — March 2024; 3 TB of sensitive patient and staff data claimed; one of the first major public-sector attacks by this group; data published after ransom refused. The Register
- Xerox Business Solutions (technology/US) — 2024; confirmed breach via Xerox public disclosure.
- Framesi (professional beauty/cosmetics manufacturing, Italy) — DLS claim seen 2026-06-17.
- Jasper Plastics Solutions (manufacturing, US) — DLS claim seen 2026-06-17.
- Belpointe Asset Management (financial services/US) — DLS claim June 15, 2026. 🟥 Unverified.
- Newspaper Media Group (media/publishing/US) — DLS claim June 20, 2026. 🟥 Unverified.
- Horizon Family Medical Group (healthcare/US; Hudson Valley, NY) — DLS claim June 18, 2026; 7 TB claimed including patient records, SQL databases, and QuickBooks data. 🟥 Unverified. DeXpose
- Horizon Eye Care (healthcare/ophthalmology/US) — DLS claim June 23, 2026. 🟥 Unverified.
- Horton Personal Injury Lawyers (legal/US) — DLS claim June 26, 2026; part of the documented June 2026 law-firm campaign surge. 🟥 Unverified.
- Law Office of John Dufour (legal/US) — DLS claim June 26, 2026. 🟥 Unverified.
- Roundshield Partners LLP (private equity/UK) — DLS claim July 1, 2026; 400 GB claimed; London-headquartered mid-market PE firm. 🟥 Unverified.
- Colorado Rehabilitation & Occupational Medicine (healthcare/US) — DLS claim July 2, 2026; data scope unconfirmed. 🟥 Unverified.
- Oak Park (Michigan) (local government/city/US; Metro Detroit, Michigan) — DLS claim July 3, 2026; attack estimated July 2; Oakland County suburb; data scope unconfirmed. 🟥 Unverified.
- Louisville Bar Association (legal/professional association/US; Kentucky) — DLS claim August 8, 2026; consistent with sustained 2026 legal-sector campaign; no victim statement; data scope unconfirmed. 🟥 Unverified.
Assessment¶
INC Ransom is a durable, high-volume RaaS with consistent growth since 2023, reaching 885+ cumulative victims as of August 2, 2026. The Rust cross-platform encryptor, Veeam-specific credential dumper, and the 2026 SonicWall SMA 1000 purpose-built toolchain (KNUCKLEBALL/Suo5/ORANGETAIL) confirm sustained R&D investment — this is not a commodity kit. The July 2026 forensic confirmation that INC Ransom and Lynx share at least one operator (simultaneous negotiation-panel logins) resolves a months-long question; treat them as a single threat cluster for defensive planning. The FortiBleed campaign (CVE-2026-24858) delivered 430,000 firewalls targeted, 354 confirmed intrusions, and 73,000 harvested credential sets — a pre-positioned access inventory available for follow-on ransomware or resale. The June 2026 SonicWall SMA 1000 campaign (CVE-2026-15409/15410 CVSS 10.0/7.2) added a new exploit-first initial access vector; the confirmed MFA seed theft means patching alone is insufficient — environments hit before patch release require full MFA credential rotation. Top targeted sectors in 2026: Legal Services (#1, deliberate campaign targeting client-privilege data), Manufacturing, Healthcare, Technology, Construction. Organizations with Citrix, Fortinet/Fortigate, or SonicWall SMA 1000 exposure should treat INC/Lynx as an active near-term threat requiring immediate patch verification and MFA audit.
Sources¶
- Sophos — GOLD IONIC Deploys INC Ransomware
- MITRE ATT&CK — INC Ransom / GOLD IONIC, Group G1032
- Australian Cyber Security Centre — INC Ransom affiliate model advisory
- Halcyon — INC Ransom campaign against law firms
- Acronis — From emerging threat to top-tier RaaS: The evolution of INC ransomware
- The Hacker News — INC Ransomware claims 830+ victims since 2023
- The Register — INC Ransom claims NHS Scotland attack
- Dark Reading — INC Ransomware Thrives by Mastering the Basics
- BleepingComputer — FortiBleed: INC Ransom and Lynx confirmed as same operator cluster (July 2026)
- SecurityWeek — FortiBleed CVE-2026-24858: 430,000 firewalls targeted, INC Ransom/Lynx linked
- The Hacker News — FortiBleed Campaign: INC Ransom = Lynx, scale data revealed (July 2, 2026)
- The Hacker News — INC Ransomware SonicWall SMA 1000 zero-day chain (CVE-2026-15409/15410)
- Resecurity — From WSProxy to Root: INC Ransomware and SonicWall SMA Exploit Chain
- CyberScoop — Prolific ransomware group behind SonicWall zero-day attacks
- Picus Security — INC Ransomware: Healthcare and Education targeting
🗂️ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
August 2026
July 2026
June 2026