INC Ransomware Exploits Unpatched Systems and Veeam Credentials to Compromise 830+ Victims
INC Ransomware has become a major Ransomware-as-a-Service (RaaS) threat by targeting public-facing application vulnerabilities and extracting credentials stored in Veeam backup solutions — a critical misstep that turns recovery tools into attack vectors. The group's ability to rewrite encryptors in Rust for both Windows and Linux/ESXi environments demonstrates technical sophistication that bypasses many legacy defenses. With over 830 victims since 2023 and spawning related families like Lynx and Sinobi, INC illustrates how a single well-resourced RaaS operation can multiply its impact across the ecosystem. Organizations that fail to patch internet-facing applications promptly and secure backup infrastructure credentials are disproportionately exposed to this type of double-extortion ransomware campaign.
Tactical Insight
Immediate Actions
- Audit and rotate all credentials stored within or accessible by Veeam backup systems and similar backup platforms immediately.
- Identify and patch all known vulnerabilities in public-facing applications, prioritizing those listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- Isolate backup infrastructure from general network access to prevent credential harvesting.
Long-Term Improvements
- Implement immutable, offline, or air-gapped backup copies following the 3-2-1-1 backup rule to ensure ransomware cannot corrupt all recovery points.
- Deploy network segmentation to limit lateral movement between public-facing systems, internal infrastructure, and backup environments.
- Establish a formal vulnerability management program with SLA-based patch timelines based on CVSS severity scores.
Detection Measures
- Enable behavioral monitoring and alerting on credential dumping activity, especially from backup software processes.
- Deploy EDR/XDR solutions capable of detecting Rust-compiled binaries and anomalous encryption activity on both Windows and Linux/ESXi hosts.
- Continuously monitor for indicators of compromise (IOCs) associated with INC, Lynx, and Sinobi ransomware families using threat intelligence feeds.