Actor · RaaS · since 2023
INC Ransom: healthcare and education in the crosshairs
Profile of INC Ransom, a RaaS active since July 2023 that gets in through RDP, phishing and Citrix, targets hospitals, schools and government, and leaks data.
- Model
- RaaS · since 2023-07
- Aliases
- INC, Inc. Ransom
- Ways in
- Valid credentials over RDP · Spear phishing · Citrix NetScaler (CVE-2023-3519) · Access handed off from Gootloader
- Targets
- Healthcare · Education · Government · Windows and Linux/ESXi servers
By Sentrix · Published 2026-09-20
Who they are
INC Ransom is an extortion operation that emerged in July 2023, according to SentinelOne. Huntress spotted its first victims on the leak site on August 8 and 9, 2023 and published, on August 11, 2023, the analysis of a complete intrusion. The group runs as ransomware-as-a-service: BleepingComputer, relaying Microsoft, describes affiliates that have targeted public and private organizations since July 2023.
The group's pitch is unusual: it presents itself as a service that "saves the reputation" of the victim by explaining its weaknesses, according to SentinelOne. The model remains double extortion, encryption plus data theft, with files carrying the .inc extension and notes named inc-readme.txt and inc-readme.html, according to Huntress.
The most documented affiliate is Vanilla Tempest, tracked by Microsoft: formerly Vice Society, active since June 2021 and a regular in education and healthcare, it adopted INC as its payload after BlackCat and Rhysida, according to BleepingComputer's September 18, 2024 report. The same article reports that in May 2024, an actor named "salfetka" put the source code of the Windows and Linux/ESXi encryptors up for sale for 300,000 US dollars.
How they get in
In the intrusion analyzed by Huntress in August 2023, compromised valid credentials were used to log in over RDP; seven days separated initial access from encryption. SentinelOne adds spear phishing and exploitation of vulnerable services, in particular CVE-2023-3519 in Citrix NetScaler. In the Vanilla Tempest case, access was handed off: Microsoft describes a Gootloader infection operated by Storm-0494, then the Supper backdoor, AnyDesk and MEGA, lateral movement over RDP and final deployment through WMI, according to BleepingComputer.
The tooling is mundane, and that is what makes it effective: Advanced IP Scanner, PuTTY, lsassy for credentials, 7-Zip for archiving, MEGAsync for exfiltration, PsExec to launch the encryptor, and the native Windows binaries net.exe, nltest.exe and wmic.exe, according to Huntress. SentinelOne adds NETSCAN, ESENTUTL and AnyDesk.
What they have done
- August 2023: first victims. Huntress identifies an Austrian hotel as the first public victim and describes a seven-day intrusion carried out entirely with legitimate tools.
- March 2024: NHS Dumfries and Galloway. The Record reports on March 29, 2024 that INC Ransom claimed the attack on this Scottish health board, which serves approximately 150,000 people, and published samples of clinical data while threatening to release more.
- September 2024: US healthcare. Microsoft observes Vanilla Tempest deploying INC for the first time against the US healthcare sector, according to BleepingComputer, from Gootloader access supplied by Storm-0494.
What stops them
- No exposed RDP, MFA on all remote access. The intrusion documented by Huntress begins with a valid credential over RDP; remote access behind a VPN with MFA, or better a bastion host, removes that door. ISO 27001:2022, 8.5 and 8.20; SOC 2, CC6.1.
- Gateway patching. CVE-2023-3519 in Citrix NetScaler is among the vectors cited by SentinelOne. A measured patch deadline for edge devices is part of the program, not a matter of goodwill. ISO 27001:2022, 8.8; SOC 2, CC7.1.
- Application control and monitoring of administration tools. AnyDesk, MEGAsync, Advanced IP Scanner and PsExec are legitimate; they have no place on a production server without approval. Block or alert on their appearance. ISO 27001:2022, 8.19; SOC 2, CC7.2.
- LSASS and privileged account protection. lsassy and credential dumping fail against Credential Guard, LSA protection and tiered administrative accounts. ISO 27001:2022, 8.2 and 8.5.
- Exfiltration detection. A 7-Zip archive leaving for MEGA is visible to anyone watching outbound traffic; DNS and proxy filtering of unapproved file sharing services stops exfiltration before the ransom note. ISO 27001:2022, 8.12 and 8.16.
- Isolated backups and continuity plans for essential services. For a hospital or a school, the question is not whether to pay, it is how to treat patients and teach without systems for weeks. ISO 27001:2022, 8.13 and 5.30; SOC 2, A1.2.
Sources
- Huntress, Investigating New INC Ransom Group Activity (August 11, 2023)
- SentinelOne, Inc. Ransomware: Analysis, Detection, and Mitigation
- BleepingComputer, Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware (September 18, 2024)
- The Record, Ransomware gang leaks stolen Scottish healthcare patient data in extortion bid (March 29, 2024)
Frequently asked questions
- Why does INC Ransom target healthcare and education?
- Because its affiliates do. SentinelOne describes an operation that strikes with little discrimination, healthcare, education and government included, and Microsoft ties the affiliate Vanilla Tempest, formerly Vice Society and a regular in those sectors since 2021, to INC. These organizations combine legacy systems, broad remote access and zero tolerance for downtime, three factors that favor payment.
- What is the first signal to watch for?
- A successful RDP login with a valid account from an unknown address, followed by administration tools that are not part of your estate: Advanced IP Scanner, AnyDesk, MEGAsync, PsExec. In the intrusion analyzed by Huntress, seven days separated that first access from encryption, a window wide enough for a detection team that knows what to look for.
- Does the sale of the source code change anything?
- It multiplies the actors able to use the encryptor. BleepingComputer reports that in May 2024, the Windows and Linux/ESXi versions were offered for sale on hacking forums. Other brands can therefore reuse the same binary with different intrusion techniques. Your controls should target behaviors, remote access, credential dumping, exfiltration, rather than a file signature.
Let's talk about your compliance program.
Last updated: 2026-09-20
