Skip to content

🇷🇺 INC Ransom

Threat-actor battle card · maintained from public sources · last updated 2026-08-09 · also known as GOLD IONIC, IncRansom, Inc. Ransom

CategoryRansomware-as-a-Service
AttributionRussian-speaking (suspected); tracked as GOLD IONIC by Sophos/Secureworks; MITRE ATT&CK Group G1032
First seen2023-08
StatusActive
Victims L3M
Victims YTD
Primary targetsLegal, Manufacturing, Healthcare, Technology, Construction

Overview

INC Ransom (also known as GOLD IONIC) is a ransomware-as-a-service (RaaS) group that emerged in August 2023 and has grown into one of the most prolific ransomware operations in 2026, claiming over 885 victims since launch (as of August 2, 2026; up from 830+ reported in June 2026). US organizations account for over 65% of victims. Top targeted sectors: legal services, manufacturing, healthcare, technology, and construction. The group runs a structured affiliate programme and has attracted experienced operators from disrupted ransomware operations. No publicly confirmed operator identities; cybersecurity researchers attribute Russian-speaking criminal involvement.

Tradecraft

  • Initial access: Spear-phishing, IAB-purchased credentials, and exploitation of public-facing application vulnerabilities — notably CVE-2023-3519 (Citrix NetScaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM), CVE-2025-5777 (Citrix NetScaler Bleed 2), CVE-2026-24858 (FortiCloud SSO SAML assertion bypass, CVSS 9.8; mass exploitation began June 2026 — see FortiBleed below), CVE-2026-15409 (SonicWall SMA 1000, CVSS 10.0 — unauthenticated WebSocket tunnel to restricted services) chained with CVE-2026-15410 (SonicWall SMA 1000, CVSS 7.2 — root privilege escalation) for full RCE/takeover; pre-disclosure exploitation by threat cluster UTA0533 confirmed from June 22, 2026; patched mid-July 2026 but exploitation continued post-patch with confirmed MFA seed theft — patching alone is insufficient, full credential/MFA reset required.
  • Encryptor: Rust-based cross-platform locker (Windows and Linux/ESXi builds); complicates static analysis and enables efficient cross-platform campaigns.
  • Extortion model: Double extortion — data exfiltration before encryption, threat of public DLS release.
  • Printer ransom-note delivery: On successful encryption, the malware scans the compromised network for active printers and automatically prints physical copies of the ransom demand — a documented escalation tactic since 2024.
  • SonicWall intrusion toolchain (2026): Post-exploitation tools deployed in the SMA 1000 chain — KNUCKLEBALL (Python launcher), Suo5 (HTTP tunnel proxy over HTTP/S), ORANGETAIL (custom Java webshell with Behinder-like capabilities) — confirm a purpose-built toolkit distinct from the general affiliate toolset.
  • Backup targeting: Modified credential dumper supporting Veeam's salted DPAPI encryption (newer deployments), specifically designed to compromise backup infrastructure and eliminate recovery options.
  • Hands-on-keyboard style: Uses legitimate remote-management tools for lateral movement (consistent with affiliate operating procedures from post-LockBit/RansomHub disruption pool).
  • Recent surge (June 2026): Claimed attacks against 10 law firms and legal services organizations within a 48-hour window — indicates a coordinated affiliate campaign against the legal sector.
  • INC Ransom = Lynx (forensic confirmation, July 2026): Independent forensic analysis and real-time operator tracking confirmed that a single operator was simultaneously logged into both an INC Ransom and a Lynx negotiation panel during active negotiations — corroborating prior code-level analysis that the two operations share infrastructure and personnel. Scale from the FortiBleed campaign: 430,000 FortiGate firewalls targeted, 354 completed intrusions, 12 ransomware deployments, approximately 20 members, 200+ operational servers, and approximately 73,000 harvested credential sets found in a publicly exposed server.

Notable victims

  • NHS Scotland (Dumfries and Galloway) — public health/UK — March 2024; 3 TB of sensitive patient and staff data claimed; one of the first major public-sector attacks by this group; data published after ransom refused. The Register
  • Xerox Business Solutions (technology/US) — 2024; confirmed breach via Xerox public disclosure.
  • Framesi (professional beauty/cosmetics manufacturing, Italy) — DLS claim seen 2026-06-17.
  • Jasper Plastics Solutions (manufacturing, US) — DLS claim seen 2026-06-17.
  • Belpointe Asset Management (financial services/US) — DLS claim June 15, 2026. 🟥 Unverified.
  • Newspaper Media Group (media/publishing/US) — DLS claim June 20, 2026. 🟥 Unverified.
  • Horizon Family Medical Group (healthcare/US; Hudson Valley, NY) — DLS claim June 18, 2026; 7 TB claimed including patient records, SQL databases, and QuickBooks data. 🟥 Unverified. DeXpose
  • Horizon Eye Care (healthcare/ophthalmology/US) — DLS claim June 23, 2026. 🟥 Unverified.
  • Horton Personal Injury Lawyers (legal/US) — DLS claim June 26, 2026; part of the documented June 2026 law-firm campaign surge. 🟥 Unverified.
  • Law Office of John Dufour (legal/US) — DLS claim June 26, 2026. 🟥 Unverified.
  • Roundshield Partners LLP (private equity/UK) — DLS claim July 1, 2026; 400 GB claimed; London-headquartered mid-market PE firm. 🟥 Unverified.
  • Colorado Rehabilitation & Occupational Medicine (healthcare/US) — DLS claim July 2, 2026; data scope unconfirmed. 🟥 Unverified.
  • Oak Park (Michigan) (local government/city/US; Metro Detroit, Michigan) — DLS claim July 3, 2026; attack estimated July 2; Oakland County suburb; data scope unconfirmed. 🟥 Unverified.
  • Louisville Bar Association (legal/professional association/US; Kentucky) — DLS claim August 8, 2026; consistent with sustained 2026 legal-sector campaign; no victim statement; data scope unconfirmed. 🟥 Unverified.

Assessment

INC Ransom is a durable, high-volume RaaS with consistent growth since 2023, reaching 885+ cumulative victims as of August 2, 2026. The Rust cross-platform encryptor, Veeam-specific credential dumper, and the 2026 SonicWall SMA 1000 purpose-built toolchain (KNUCKLEBALL/Suo5/ORANGETAIL) confirm sustained R&D investment — this is not a commodity kit. The July 2026 forensic confirmation that INC Ransom and Lynx share at least one operator (simultaneous negotiation-panel logins) resolves a months-long question; treat them as a single threat cluster for defensive planning. The FortiBleed campaign (CVE-2026-24858) delivered 430,000 firewalls targeted, 354 confirmed intrusions, and 73,000 harvested credential sets — a pre-positioned access inventory available for follow-on ransomware or resale. The June 2026 SonicWall SMA 1000 campaign (CVE-2026-15409/15410 CVSS 10.0/7.2) added a new exploit-first initial access vector; the confirmed MFA seed theft means patching alone is insufficient — environments hit before patch release require full MFA credential rotation. Top targeted sectors in 2026: Legal Services (#1, deliberate campaign targeting client-privilege data), Manufacturing, Healthcare, Technology, Construction. Organizations with Citrix, Fortinet/Fortigate, or SonicWall SMA 1000 exposure should treat INC/Lynx as an active near-term threat requiring immediate patch verification and MFA audit.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

August 2026

Aug 11 Otter Tail County INC Ransom Ransomware · Government · USA INC Ransom DLS claim posted August 17, 2026; attack estimated August 11. County government (population ~60,000, west-central Minnesota). Scope unconfirmed. · Sources: https://www.ransomware.live/id/T3R0ZXIgVGFpbCBDb3VudHksIE1pbm5lc290YUBpbmNyYW5zb20=
Aug 10 ATMS & Co. LLP INC Ransom Ransomware · Professional Services · IN Chartered accountant firm; INC_RANSOM DLS posting August 10, 2026; part of INC's SonicWall SMA 1000 exploitation campaign (CVE-2026-15409/CVE-2026-15410 CVSS 10.0); data scope unconfirmed · Sources: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Aug 08 Louisville Bar Association INC Ransom Ransomware · Legal / Professional Association · US INC Ransom DLS claim August 8 2026; Kentucky-based legal professional association; consistent with INC Ransom sustained 2026 legal-sector campaign; no victim statement; data scope unconfirmed · Sources: https://www.ransomware.live/group/incransom

July 2026

Jul 30 Kontact Consortium India INC Ransom Ransomware · engineering and manufacturing · India INC_RANSOM DLS claim July 30, 2026; Indian engineering and manufacturing company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 25 Health Law Advocates INC Ransom Ransomware · legal-nonprofit · US Boston non-profit legal organization; INC Ransom DLS posting July 26 2026, estimated attack date July 25; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://www.ransomware.live/
Jul 18 Reatile Group INC Ransom Ransomware · energy (industrial/energy distribution) · South Africa INC Ransom DLS posting July 18; data claimed exfiltrated; unverified — no public statement from Reatile Group · Sources: https://www.ransomware.live
Jul 18 D.MAG New Material Technology INC Ransom Ransomware · manufacturing (advanced materials) · China INC Ransom DLS posting July 18; data claimed exfiltrated; unverified — no public statement from D.MAG · Sources: https://www.ransomware.live
Jul 08 Aesthetic Surgical Images INC Ransom Ransomware · healthcare · plastic surgery/US INC Ransom DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/incransom · Sources: [SharkStriker] · [ransomware.live]
Jul 03 Oak Park INC Ransom Ransomware · local government · city/US Metro Detroit suburb in Oakland County; INC Ransom DLS claim July 3, 2026; attack estimated July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 City of Acworth, Georgia INC Ransom Ransomware · local government · US suburban Atlanta city northwest of the city; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 Carvalima Transportes INC Ransom Ransomware · transportation-logistics · Portugal road transport and logistics company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 Estrutural Zortéa INC Ransom Ransomware · construction · Brazil Brazilian construction and infrastructure company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 02 Colorado Rehabilitation & Occupational Medicine INC Ransom Ransomware · healthcare · US Colorado-based rehabilitation and occupational medicine practice; INC Ransom DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 01 Roundshield Partners LLP INC Ransom Ransomware · financial services · private equity/UK UK-based private equity firm focused on special situations and credit investments; INC Ransom DLS claim July 1, 2026; 400 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]

June 2026

Jun 29 GDN AR INC Ransom Ransomware · grocery · food retail/Argentina Argentine grocery store operator headquartered in Ciudad Autónoma de Buenos Aires; INC Ransom DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/R0ROIEFSKERvcmlua2EpQGluY3JhbnNvbQ · Sources: [ransomware.live]
Jun 26 callhorton.com INC Ransom Ransomware · legal services · US personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26 johndufourlaw.com INC Ransom Ransomware · legal services · US personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26 Life Bridges INC Ransom Ransomware · non-profit · social services/US non-profit organisation supporting individuals with intellectual and developmental disabilities; INC Ransom DLS claim June 25-26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/incransom-targets-life-bridges-non-profit-in-ransomware-attack/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 23 Belpointe Asset Management INC Ransom Ransomware · financial advisory · investment/US https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23 Horizon Eye Care INC Ransom Ransomware · healthcare · ophthalmology/US comprehensive eye exam and corrective-vision services provider (LASIK, cataract, contact lens, designer eyewear); DLS claim June 23; data scope and impact unconfirmed; no Horizon Eye Care statement · https://www.redpacketsecurity.com/incransom-ransomware-victim-horizoneye-com/ · https://www.ransomware.live/group/incransom · Sources: [RedPacket Security] · [ransomware.live]
Jun 21 jktornel INC Ransom Ransomware · sector unknown · — client data, proprietary information claimed · Sources: ransomware.live DLS
Jun 20 Newspaper Media Group INC Ransom Ransomware · media · publishing/US US-based local news organization operating community newspapers and magazines across Central and South Jersey; DLS claim June 20, 2026; data scope and impact unconfirmed; no public statement from victim · https://www.redpacketsecurity.com/incransom-ransomware-victim-newspaper-media-group/ · Sources: [RedPacket Security]
Jun 18 Horizon Family Medical Group INC Ransom Ransomware · healthcare · US 7TB of sensitive data claimed exfiltrated; includes patient medical records (diagnoses, prescriptions, treatments, lab results), SQL databases, and QuickBooks financial data; victim management notified but did not respond per INC Ransom; 🟥 unconfirmed — no Horizon public statement · https://www.dexpose.io/incransom-compromises-horizon-family-medical-group/ · https://www.ransomware.live/group/incransom · https://malware.news/t/incransom-compromises-horizon-family-medical-group/108055 · Sources: [DeXpose] · [ransomware.live] · [Malware News]
Jun 17 Framesi INC Ransom Ransomware · professional beauty · cosmetics manufacturing/Italy Sources: ransomware.live DLS
Jun 17 Jasper Plastics Solutions INC Ransom Ransomware · manufacturing · US Sources: ransomware.live DLS

← All threat actors · Full victim database →