Description Summary
INC Ransom is a ransomware group active since July 2023. Its source code was advertised for sale in May 2024 and subsequently became the basis for the Lynx ransomware family. INC has attacked municipal governments, healthcare, and large enterprises including Xerox Business Solutions and several U.S. school districts.
Threat Actor
Closed group; codebase later sold and reused as Lynx.
Technical Indicators
Encryption Extension
.INC
Encryption Algorithm
AES-128 (CTR) + Curve25519
Ransom Note Name
INC-README.txt
Targeted Industries
Healthcare, Government, Education, Manufacturing
First Seen
July 2023
Last Seen
Active
Geographical Location
United States, Europe
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |