The ransomware landscape continues to evolve at a rapid pace, with new threat groups emerging to fill the vacuum left by disrupted cybercriminal operations.
According to new research from the Acronis Threat Research Unit (TRU), INC ransomware has grown from a relatively unknown ransomware-as-a-service (RaaS) operation in 2023 into one of the world’s most active ransomware groups in 2026. Since first appearing, the group has claimed more than 800 victims globally and has become a significant player in the cybercrime ecosystem.
One finding that stands out for Australian organisations is the country’s continued presence among the most frequently targeted nations identified in INC ransomware victim disclosures. While the United States accounts for the majority of victims, Australia ranks among the leading countries affected by the group, highlighting the ongoing exposure of Australian businesses to modern ransomware campaigns.
INC’s rise reflects a broader shift within the ransomware ecosystem. Following law enforcement actions against major ransomware operations such as LockBit and the shutdown of BlackCat, many affiliates have migrated to alternative ransomware platforms. INC appears to have benefited from this disruption, rapidly expanding both its affiliate network and operational capabilities.
The group’s technical development has also accelerated. Researchers observed that both the Windows and Linux/ESXi variants of INC ransomware have been rewritten in Rust, a programming language increasingly adopted by cybercriminals because it enables easier cross-platform development and can complicate malware analysis.
In addition to improvements in its ransomware payloads, INC has continued to refine supporting tools used throughout the attack lifecycle. Recent incidents analysed by Acronis researchers revealed an updated credential-dumping utility capable of extracting credentials from newer Veeam backup environments. This development demonstrates the group’s focus on compromising backup infrastructure, a tactic commonly used by ransomware operators to reduce a victim’s ability to recover without paying a ransom.
Like many modern ransomware groups, INC relies on a combination of opportunistic and targeted attack methods. Initial access is commonly achieved through compromised credentials, phishing campaigns, or exploitation of internet-facing vulnerabilities. Once inside a network, attackers conduct reconnaissance, move laterally across systems, exfiltrate sensitive information and ultimately deploy encryption across targeted environments.
The industries most frequently targeted by INC ransomware include legal services, manufacturing, technology, healthcare and construction. These sectors often depend heavily on operational continuity, making downtime particularly costly and increasing pressure on organisations during ransomware incidents.
For Australian businesses, the findings highlight the importance of maintaining a proactive cybersecurity posture. As ransomware operators continue to adapt their tactics and toolsets, organisations should prioritise securing backup infrastructure, implementing multi-factor authentication, maintaining robust patch management practices and monitoring for signs of credential theft.
“While the United States remains the primary target, Australia continues to appear among the most affected countries in INC ransomware victim disclosures,” said Darrel Virtusio, Threat Research Evangelist at Acronis.
“The evolution of INC demonstrates how quickly ransomware operators can adapt following disruptions to major cybercriminal groups. We are seeing threat actors invest in more advanced tooling, expand affiliate networks and increasingly target technologies that organisations rely on for business continuity and recovery.”
Virtusio added that organisations should pay particular attention to exposed remote services and identity security controls.
“Many ransomware attacks still begin with compromised credentials or unpatched internet-facing systems. Strengthening these areas remains one of the most effective ways to reduce overall ransomware risk.”
As ransomware groups continue to evolve, the rise of INC serves as a reminder that the disappearance of one cybercriminal organisation rarely results in a reduction of overall threat activity. Instead, new groups rapidly emerge, often inheriting affiliates, tactics and operational knowledge from their predecessors.
For Australian organisations, staying resilient against ransomware requires continuous vigilance, strong cyber hygiene and an understanding of how the threat landscape is changing.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
Source research:
https://www.acronis.com/en/tru/posts/from-emerging-threat-to-top-tier-ransomware-as-a-service-the-evolution-of-inc-ransomware/
Last Updated on June 18, 2026 by Nick Ross



