Back to all lessons
Awareness Lessons
4 months ago

INC Ransomware Exploits Unpatched Systems and Veeam Credentials to Compromise 830+ Victims

INC Ransomware has become a major Ransomware-as-a-Service (RaaS) threat by targeting public-facing application vulnerabilities and extracting credentials stored in Veeam backup solutions — a critical misstep that turns recovery tools into attack vectors. The group's ability to rewrite encryptors in Rust for both Windows and Linux/ESXi environments demonstrates technical sophistication that bypasses many legacy defenses. With over 830 victims since 2023 and spawning related families like Lynx and Sinobi, INC illustrates how a single well-resourced RaaS operation can multiply its impact across the ecosystem. Organizations that fail to patch internet-facing applications promptly and secure backup infrastructure credentials are disproportionately exposed to this type of double-extortion ransomware campaign.

Tactical Insight

Immediate Actions

  • Audit and rotate all credentials stored within or accessible by Veeam backup systems and similar backup platforms immediately.
  • Identify and patch all known vulnerabilities in public-facing applications, prioritizing those listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
  • Isolate backup infrastructure from general network access to prevent credential harvesting.

Long-Term Improvements

  • Implement immutable, offline, or air-gapped backup copies following the 3-2-1-1 backup rule to ensure ransomware cannot corrupt all recovery points.
  • Deploy network segmentation to limit lateral movement between public-facing systems, internal infrastructure, and backup environments.
  • Establish a formal vulnerability management program with SLA-based patch timelines based on CVSS severity scores.

Detection Measures

  • Enable behavioral monitoring and alerting on credential dumping activity, especially from backup software processes.
  • Deploy EDR/XDR solutions capable of detecting Rust-compiled binaries and anomalous encryption activity on both Windows and Linux/ESXi hosts.
  • Continuously monitor for indicators of compromise (IOCs) associated with INC, Lynx, and Sinobi ransomware families using threat intelligence feeds.