Actor Profile
INC is a ransomware-as-a-service (RaaS) operation that has emerged as a major threat actor since August 2023. The group operates a multi-affiliate model, providing ransomware tooling and infrastructure to criminal partners in exchange for a share of ransom payments. INC's motivation is financially driven, focusing on extortion through data encryption and exfiltration. The operation has demonstrated significant growth by capitalizing on law enforcement disruptions of competing RaaS platforms, absorbing displaced affiliates from dismantled or disrupted operations.
TTPs (Tactics, Techniques, Procedures)
INC operates as a ransomware-as-a-service platform, employing double extortion tactics combining data encryption with exfiltration and leak threats. The group leverages multiple ransomware variants including INC-branded tools as well as LockBit and BlackCat malware families, suggesting either code reuse or affiliate overlap. The RaaS model enables distributed initial access through affiliate networks, with centralized C2 infrastructure and data leak sites managed by core operators. The operation demonstrates adaptability in recruitment and operational tempo, rapidly scaling affiliate networks following competitor disruptions.
Targets & Patterns
INC has claimed over 830 victims since August 2023, indicating an opportunistic targeting approach typical of RaaS operations. The lack of specific sector or geographic focus suggests affiliates select targets based on accessibility and perceived ability to pay rather than strategic objectives. This broad victimology pattern is consistent with financially motivated cybercrime operations that prioritize volume and ransom yield over targeted intelligence collection. The rapid victim accumulation rate indicates either a large affiliate network or highly active operators exploiting widespread vulnerabilities.
Historical Context
INC's expansion directly correlates with major law enforcement actions against competing RaaS platforms. The group experienced significant growth following the February 2024 Operation Cronos disruption of LockBit infrastructure and the March 2024 shutdown of BlackCat (ALPHV). This timing suggests INC actively recruited displaced affiliates from these operations, offering continuity of criminal services during competitor downtime. The use of LockBit and BlackCat malware variants by INC affiliates indicates technical and operational continuity, with experienced ransomware operators migrating their toolsets and methodologies to the new platform.
Defensive Recommendations
- Monitor for indicators associated with LockBit and BlackCat ransomware families, as INC affiliates may reuse these tools and infrastructure patterns
- Implement robust backup and recovery procedures with offline or immutable storage to mitigate ransomware encryption impact
- Deploy network segmentation and enforce least-privilege access controls to limit lateral movement capabilities of ransomware affiliates
- Establish detection rules for common ransomware precursor activities including credential dumping, RDP abuse, and large-scale data exfiltration
- Monitor dark web leak sites and threat intelligence feeds for early warning of INC-related compromise or data exposure
