HackMyIP
← Back to News
2026-06-17 Dark Reading

INC Ransomware Targets Healthcare with Pressure-Driven Tactics

RansomwareMalwareThreat Intel

INC Ransomware has emerged as one of the most operationally disciplined ransomware groups active in 2024-2025, achieving consistent success not through novel exploit chains or zero-day weaponization, but by ruthlessly mastering the fundamentals of ransomware economics. According to threat intelligence tracked by Dark Reading, the group has methodically concentrated its attacks on sectors where operational disruption translates directly into urgent ransom demands, with healthcare organizations remaining a primary target. INC's operators understand that when hospital systems go dark, surgical schedules halt, and patient records become inaccessible, the pressure to pay escalates within hours, not days.

The group's tradecraft reflects a calculated reliance on proven initial access vectors. INC affiliates have been observed leveraging spear-phishing campaigns delivering IcedID and Brute Ratel C4 payloads, exploiting unpatched VPN appliances such as Cisco ASA and Fortinet FortiGate, and abusing legitimate remote management tools like AnyDesk and Atera for lateral movement. Once inside a network, operators use Mimikatz and custom credential dumpers to harvest domain admin privileges, then deploy Cobalt Strike beacons for persistence before exfiltrating data via Mega.nz and rclone transfers. Their double-extortion model publishes stolen data on their Tor-based leak site, "INC PAY," applying additional pressure on victim organizations already struggling with operational continuity.

For security teams in healthcare and other high-value verticals, the INC playbook underscores that foundational hygiene remains the strongest deterrent. Regularly auditing internet-facing appliances, enforcing multi-factor authentication on all remote access points, and segmenting clinical networks from administrative systems can disrupt the lateral movement INC affiliates depend on. IT administrators should use a port scanner to verify that no unexpected services are exposed on perimeter devices, while employees handling sensitive credentials can validate them through a password checker to ensure no compromised logins are in circulation. Organizations concerned about data exposure can also run a email breach checker against employee addresses to identify accounts already circulating on dark-web forums.

INC's success demonstrates a recurring lesson in threat intelligence: ransomware operators don't need sophisticated zero-day capabilities when their targets leave well-known doors unlocked. As the group continues refining its pressure-based targeting, defenders must treat basic controls, including timely patching, privileged access management, and immutable offline backups, as mission-critical. The groups that master the basics on the defensive side will be the ones who deny INC and its peers the easy wins they depend on.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →