◇ SIGN IN
← all actors
ransomware

IncRansom

activemedium confidence
Ransomware
INC RansomINC RansomwareLynx (assessed rebrand)
Attribution
RaaS (financially motivated, unattributed)
Origin
Unknown
First seen
2023
Last active
2025
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Saudi Arabia, UAE
Sectors
Energy, chemicals, training, logistics, facilities

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE (Energy, chemicals, training sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

INC Ransom is a double-extortion ransomware-as-a-service operation active since 2023; researchers assess the Lynx ransomware (from mid-2024) to be a direct rebrand of INC based on very high code similarity.

History

INC Ransom emerged in 2023 as a RaaS running double-extortion attacks across healthcare, government, manufacturing and other sectors, exfiltrating data and threatening leak-site publication. In mid-2024, Lynx ransomware appeared and was assessed by Unit 42 and others as a direct rebrand of INC, with over 90% code similarity; Lynx amassed hundreds of victims through 2025. The INC/Lynx lineage illustrates the common ransomware pattern of rebranding to shed law-enforcement and reputational attention while retaining tooling.

Activity attributed to the INC/Lynx lineage continued through 2025 across manufacturing, legal, energy and other sectors, with aggressive double-extortion pressure.

INC Ransom has claimed victims in Saudi Arabia and the UAE among its listings. These are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.

Notable campaigns

2024
Lynx rebrand
Unit 42 assessed the newly appeared Lynx ransomware as a direct rebrand of INC Ransom based on >90% code overlap.
2025
Sustained double-extortion operations
The INC/Lynx lineage continued claiming hundreds of victims across manufacturing, legal and energy sectors.
2025
Gulf leak-site listings
Saudi and UAE organizations appeared on INC Ransom's leak site (claimed, not independently confirmed).

Known tooling · Ransomware Tool Matrix

Tools observed in intrusions leading to IncRansom's ransomware, per the community Ransomware Tool Matrix — observed use, not exhaustive. Snapshot 2026-08-07.

Discovery · 2
AdFindAdvanced IP Scanner
LOLBAS · 2
FingerPsExec
Exfiltration · 5
BackBlazeMEGAResticRClones5cmd

5 source reports · latest 12 March 2026

Claimed victims · 893 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Louisville Bar AssociationUSProfessional Services
ATMSINTransportation
vprj.orgUS
lantisnet.comUSTechnology
https://geleximco.vn/VNManufacturing
lccgroup.comPHProfessional Services
pushidrosal.idIDOther
TRULITE GLASS & ALUMINUM SOLUTIONSUSManufacturing
clintonhealthaccess.orgUSHealthcare
ecfa.orgUSProfessional Services
quantinuum.comUSTechnology
Oleoductos del ValleAREnergy & Utilities