[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPyoQ8w-Zs5-XFDZRorHJcoRaDuVvl76LQTclD6eU8vA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"54b5ba27-e053-49ae-98b7-1d9d73dd0600","inc-ransomware-exploits-unpatched-systems-and-veeam-credentials-to-compromise-830-victims","ab26bc48-3110-4d08-8dd2-7d49c69fda5d","INC Ransomware Exploits Unpatched Systems and Veeam Credentials to Compromise 830+ Victims","INC Ransomware has become a major Ransomware-as-a-Service (RaaS) threat by targeting public-facing application vulnerabilities and extracting credentials stored in Veeam backup solutions — a critical misstep that turns recovery tools into attack vectors. The group's ability to rewrite encryptors in Rust for both Windows and Linux\u002FESXi environments demonstrates technical sophistication that bypasses many legacy defenses. With over 830 victims since 2023 and spawning related families like Lynx and Sinobi, INC illustrates how a single well-resourced RaaS operation can multiply its impact across the ecosystem. Organizations that fail to patch internet-facing applications promptly and secure backup infrastructure credentials are disproportionately exposed to this type of double-extortion ransomware campaign.","**Immediate Actions:**\n- Audit and rotate all credentials stored within or accessible by Veeam backup systems and similar backup platforms immediately.\n- Identify and patch all known vulnerabilities in public-facing applications, prioritizing those listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.\n- Isolate backup infrastructure from general network access to prevent credential harvesting.\n\n**Long-Term Improvements:**\n- Implement immutable, offline, or air-gapped backup copies following the 3-2-1-1 backup rule to ensure ransomware cannot corrupt all recovery points.\n- Deploy network segmentation to limit lateral movement between public-facing systems, internal infrastructure, and backup environments.\n- Establish a formal vulnerability management program with SLA-based patch timelines based on CVSS severity scores.\n\n**Detection Measures:**\n- Enable behavioral monitoring and alerting on credential dumping activity, especially from backup software processes.\n- Deploy EDR\u002FXDR solutions capable of detecting Rust-compiled binaries and anomalous encryption activity on both Windows and Linux\u002FESXi hosts.\n- Continuously monitor for indicators of compromise (IOCs) associated with INC, Lynx, and Sinobi ransomware families using threat intelligence feeds.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 11: Data Recovery","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 CP-9: Information System Backup","NIST SP 800-53 AC-3: Access Enforcement","NIST CSF RS.MI-1: Incidents are contained","NIST CSF ID.RA-1: Asset vulnerabilities are identified and documented","ITIL: Problem Management — proactive identification of recurring vulnerabilities","GDPR Article 32: Security of Processing — technical measures to ensure data integrity and availability","published","2026-06-18T16:21:48.366453+00:00","2026-06-18T16:21:48.262+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Finc-ransomware-claims-830-victims-since.html","inc-ransomware-emerges-as-major-raas-threat-in-2026-with-830-victims-since-2023-913690","INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8ff5d73-dec9-4911-88ee-ed016a89f3f4","Backup & Recovery","backup-recovery","No backups, untested recovery, ransomware impact","#f43f5e",[]]