INC Ransom is a financially motivated ransomware-as-a-service operation that emerged in mid-2023. A joint advisory from the Australian Cyber Security Centre, CERT Tonga and New Zealand’s NCSC describes a division of labor in which affiliates conduct intrusions and deploy the ransomware, while the core operation maintains extortion infrastructure and handles payments. The group remained active through at least 2025, but public reporting about technical overlap with Lynx and older ransomware families does not by itself establish a common operator or confirmed rebrand.
Activity and targeting
INC Ransom affiliates have compromised organizations in multiple countries since 2023. The joint government advisory says earlier activity concentrated on the United States and United Kingdom and that targeting increased across Australia, New Zealand and Pacific island states from early 2025; it also reports a disproportionate focus on health-care organizations. Trend Micro’s 2024 research likewise found health care prominent in its telemetry and leak-site sample, alongside education, nonprofits, construction, professional services and manufacturing. Leak-site entries represent the actor’s claims and should not be treated as independently verified victim counts.
Methods and operational characteristics
Observed access routes include compromised or purchased credentials, spear-phishing and exploitation of known vulnerabilities in internet-facing systems. In one early incident, Huntress observed an operator using a compromised account and RDP, staging files with 7-Zip, installing MEGASync, accessing credentials and moving laterally before distributing the encryptor with WMIC and PsExec. The government advisory also documents the use of legitimate utilities such as 7-Zip, WinRAR and rclone for staging and exfiltration, underscoring that affiliate tradecraft can vary between intrusions.
INC Ransom uses double extortion: affiliates may steal sensitive data and encrypt systems, after which the operation threatens publication through a Tor-based data-leak site to pressure victims to pay. Trend Micro analyzed Windows and Linux variants and reported capabilities including partial or full file encryption, process termination and attempts to delete shadow copies. Encryption and data theft should still be assessed separately in each incident; an INC Ransom claim does not establish that either occurred.
What type of group is it?
INC Ransom is best characterized as a financially motivated cybercriminal service and affiliate network, not as a single intrusion team with an invariant playbook. That structure means access methods, tooling and target selection may reflect individual affiliates as much as the core operators. The reviewed sources do not publicly identify the people directing the operation, establish their jurisdiction or support state sponsorship.