INC Ransom
Also known as Incransom, INC, Inc, INC Ransom, INC Ransom Group, INC ransomware
Reports
122
First seen
Aug 11, 2023
Last seen
Aug 14, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×1×37
United States×37
Brazil×4
Australia×3
Switzerland×3
Germany×2
Philippines×2
Spain×2
Japan×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×15T1190 Exploit Public-Facing Application ×7T1041 Exfiltration Over C2 Channel ×6T1562.001 Impair Defenses: Disable or Modify Tools ×6T1566 Phishing ×5T1110 Brute Force ×5T1078 Valid Accounts ×5T1021.002 SMB/Windows Admin Shares ×5T1567 Exfiltration Over Web Service ×4T1219 Remote Access Software ×4T1021 Remote Services ×3T1005 Data from Local System ×3
Indicators
domain ×173ip_v4 ×64filename ×49cve ×19hash_sha256 ×7url ×4hash_md5 ×4hash_sha1 ×3email ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2026-15410 (exploited)CVE-2026-15409 (exploited)CVE-2023-48788 (exploited)CVE-2024-1709 (exploited)CVE-2024-57727 (exploited)CVE-2025-5777 (exploited)CVE-2026-20131 (exploited)CVE-2026-33825 (exploited)CVE-2026-35616 (exploited)CVE-2026-50751 (exploited)CVE-2026-50752CVE-2026-56155 (exploited)CVE-2026-56164 (exploited)CVE-2026-60137 (exploited)CVE-2022-40684 (exploited)CVE-2026-63030 (exploited)CVE-2023-3519 (exploited)
Recent reports
High