INC Ransomware Fills the LockBit Vacuum, Racks Up 830+ Victims

Two years after a quiet debut, INC has graduated from boutique RaaS to one of 2026's busiest extortion brands — riding the affiliate exodus from LockBit and BlackCat.

ThreatVectr Newsdesk· 2 min read
INC Ransomware Fills the LockBit Vacuum, Racks Up 830+ Victims
Share

INC was a footnote when it surfaced in August 2023. It is not a footnote anymore.

Researchers tracking the group's victim count now put the total at more than 830 organizations posted to its leak site, a trajectory that puts INC in the same conversation as the household-name crews it effectively replaced. The growth curve is not subtle. It tracks almost exactly with the law-enforcement disruption of LockBit and the exit-scam collapse of BlackCat/ALPHV in early 2024.

Affiliates, it turns out, are loyal to infrastructure, not brands.

When Operation Cronos seized LockBit's panels and BlackCat's operators walked off with their own affiliates' commissions, the people actually running intrusions needed a new shop. INC was already standing up a Russian-speaking affiliate program, splitting profits on the usual 80/20 model, and shipping a builder that produced both Windows and ESXi payloads. The timing was good. For them.

The technical kit is not exotic. INC's payload is a fairly conventional ChaCha20-plus-RSA hybrid, with the usual shadow-copy deletion, service-stopping routines, and a partial-encryption mode for large files to speed throughput on VMware datastores. If you've reverse-engineered any post-Conti spinoff, you've seen most of this before. The novelty is operational, not cryptographic.

Initial access trends with the rest of the ecosystem: phished credentials, exposed Citrix and Fortinet appliances, and the occasional IAB-supplied foothold into Veeam or backup infrastructure. Lateral movement leans on AnyDesk, PuTTY, and PsExec. Exfil rides MEGA and Rclone. None of this should surprise anyone who has read a Mandiant report in the last three years.

What makes INC worth watching is the targeting mix.

Healthcare has taken an outsized share of the hits, including a high-profile attack on NHS Dumfries and Galloway in 2024 that leaked patient records. Manufacturing, construction, and US municipal targets round out the list. A splinter calling itself Lynx appeared in mid-2024 using what looked like recompiled INC source, which is either a rebrand, a leak, or a franchise dispute. Possibly all three.

Defenders should treat INC the way they treated LockBit in 2022: assume affiliates have your edge-device CVEs bookmarked. Patch your Citrix NetScaler (CVE-2023-4966 is still being exploited, somehow), enforce phishing-resistant MFA on VPN and admin portals, and segment backup infrastructure off the production domain. Hunt for Rclone binaries in places Rclone has no business being.

The RaaS market abhors a vacuum. INC simply walked into one.

© 2026 Threat Vectr