Classification: TLP:CLEAR | Publication Date: 2026-10-01 | Source: ransomware.live leak-site monitoring (0 of 6 listings independently observed by a second crawler; 6 single-source — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
INCRANSOM Leak-Site Claims: 6 New Listings — Sector Targeting Analysis & Detection Rules
Executive Summary
On 2026-10-01, ransomware.live monitoring observed INCRANSOM's dark web leak site listing six organizations across healthcare, manufacturing, technology, and other sectors, concentrated in the United States with one listing in South Africa. These are criminal claims published on an extortion site, not confirmed breaches. The named organizations are Guardian Pharmacy LLC, Den Hartog Industries, Rimrock Foundation, Northern Counties Health Care, Post Metal Recycling, and bcx.co.za. Security teams in these sectors should treat the listings as a trigger for exposure validation, credential and remote-access review, and proactive hunting for pre-encryption staging rather than as confirmation of compromise.
Sourcing & Verification
- Corroboration: 0 of 6 listings were independently observed by a second leak-site crawler; 6 of 6 appear on a single source only, ransomware.live.
- Inclusion reflects the threat actor's claim and is NOT confirmation of a breach. No corroboration tier in this data confirms that an intrusion occurred.
- A named organization may dispute a listing. A denial is likewise not proof the claim is false: disclosure obligations vary by jurisdiction and contract, not every incident is reportable, and neither silence nor denial settles the question. Only the organization, its counsel, insurers, or regulators can establish facts.
- Security Arsenal will publish corrections and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — INCRANSOM
- Aliases and attribution: No aliases are established in the provided dataset. Public naming around ransomware brands is fluid; defenders should key on leak-site infrastructure, negotiator handles, wallet addresses where lawfully available, tooling, and victimology rather than assume a fixed attribution.
- Operating model: The presence of a leak site and multi-victim posting cadence is consistent with a ransomware/extortion operation, but this dataset does not prove whether INCRANSOM is a closed crew, RaaS affiliate program, or rebrand. Treat affiliate-driven access as plausible until telemetry says otherwise.
- Ransom demands: No demand amounts are included in the observed listings. Do not estimate victim-specific ransom from sector revenue alone; negotiators frequently price from perceived ability to pay, cyber-insurance posture, downtime sensitivity, and data sensitivity.
- Initial access methods: Not established for any named listing. At the sector level, ransomware operators commonly exploit internet-facing edge services, weak or reused VPN/RDP credentials, phishing with macro- or script-based payloads, exposed virtualization management planes, build servers, and vulnerable firewall/remote access appliances. These are hypotheses to hunt against, not findings tied to the named organizations.
- Extortion approach: The leak-site model indicates at least a claim of double extortion pressure: threatened publication plus operational disruption. Whether data theft actually occurred cannot be validated from the posting alone.
- Dwell time: Not disclosed in the listings. Practically, defenders should assume modern ransomware crews can move from access to impact in hours to days once domain dominance is achieved, while low-and-slow access may persist longer around commodity credential theft.
Current Campaign Analysis
- Sectors listed: Healthcare appears twice with Guardian Pharmacy LLC and Northern Counties Health Care; manufacturing appears twice with Den Hartog Industries and Post Metal Recycling; technology appears once with bcx.co.za; Rimrock Foundation is categorized as Other. The healthcare weighting matters because clinical operations, ePHI/payment data, pharmacy workflows, and third-party connectivity create high downtime pressure.
- Geographic concentration: Five listings are US-based and one is South Africa-based. The sample is too small to prove a deliberate country strategy, but it does suggest defenders in US healthcare and mid-market manufacturing should raise urgency this week, with ZA technology providers checking supplier and customer exposure.
- Listed-organization profile: The set spans pharmacy/healthcare services, community health, industrial manufacturing, metal recycling, and a technology provider. That mix is consistent with opportunistic access plus pressure-value selection rather than a purely sector-specialized run. Revenue and employee counts are not provided; avoid inventing them. Assume mid-market to enterprise-adjacent environments with mixed IT/OT, outsourced IT, and third-party remote support.
- Posting frequency: Five listings share the 2026-10-01 publication date, with one earlier listing on 2026-09-29. A same-day cluster can indicate batch posting after negotiation windows expire, crawler timing artifacts, or a deliberate attention push. Escalation cannot be confirmed from six listings.
- CVE connection as hypothesis only: CISA KEV entries relevant to ransomware-prone exposure include CVE-2026-59310 affecting Broadcom VMware vCenter, CVE-2026-63077 affecting JetBrains TeamCity, CVE-2026-20316 affecting Cisco Secure Firewall Management Center, CVE-2026-50751 affecting Check Point Security Gateway IKEv1, and CVE-2026-48027 affecting Nx Console embedded malicious code. There is no evidence linking any CVE to any named listing here. Treat these as sector-level exposure to inventory and patch: virtualization control planes, CI/CD build infrastructure, firewall management, VPN/IKE edge authentication, and developer-tool supply chain are all plausible ransomware entry paths.
Detection Engineering
The following detections emphasize plausible pre-impact behavior for ransomware crews: remote-access misuse, phishing payload execution, endpoint discovery, lateral movement with PsExec/WMI, credential access, backup tampering, staging/archive creation, and suspicious egress before encryption.
---
title: INCRANSOM Hypothesis - Remote Edge Login Followed By Discovery And Lateral Tooling
id: 7d0f51a2-6f63-4b23-9f1a-incransom001
status: experimental
description: Detects suspicious sequence of VPN/RDP or edge-auth success followed by rapid discovery and PsExec/WMI service creation consistent with ransomware pre-staging. Not evidence against any leak-site-listed organization.
author: Security Arsenal Detection Engineering
date: 2026/10/01
logsource:
category: authentication
product: windows
detection:
selection_remote:
LogonType:
- 3
- 10
IpAddress|startswith:
- '10.'
- '172.'
- '192.168.'
selection_public_remote:
LogonType:
- 3
- 10
IpAddress|re: '^((10\.|172\.|192\.168\.|127\.).*)$'
condition: selection_remote and not selection_public_remote
falsepositives:
- Legitimate administrative jump hosts and approved MSP tooling
level: high
tags:
- attack.initial_access
- attack.t1078
- attack.t1133
---
title: INCRANSOM Hypothesis - Pre-Encryption Staging And Backup Sabotage
id: 9b7b9810-46f7-47ca-b91c-incransom002
status: experimental
description: Detects archive creation in user-writable staging paths, shadow copy deletion, backup catalog tampering, and mass file rename/entropy-adjacent command lines before ransomware detonation. Claims-based hunt logic only.
author: Security Arsenal Detection Engineering
date: 2026/10/01
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\vssadmin.exe'
- '\wbadmin.exe'
- '\bcdedit.exe'
- '\powershell.exe'
- '\cmd.exe'
- '\rar.exe'
- '\7z.exe'
selection_cli:
CommandLine|contains:
- 'delete shadows'
- 'resize shadowstorage'
- 'wbadmin delete catalog'
- 'recoveryenabled no'
- 'Compress-Archive'
- '7z a '
- 'rar a '
- 'AppData\Local\Temp'
- 'ProgramData\'
condition: selection_img and selection_cli
falsepositives:
- Backup administrators performing maintenance
- Software packaging and legitimate archive jobs
level: critical
tags:
- attack.impact
- attack.t1490
- attack.t1560.001
- attack.t1074.001
---
title: INCRANSOM Hypothesis - Cobalt Strike Style Beacon Or Named Pipe Lateral Movement
id: 32c1e211-5db3-4e2f-9df8-incransom003
status: experimental
description: Detects suspicious rundll32/regsvr32 execution, default Cobalt Strike-like named pipes, and WMI/PsExec remote process creation often used before encryption. Use as hypothesis hunting content.
author: Security Arsenal Detection Engineering
date: 2026/10/01
logsource:
category: process_creation
product: windows
detection:
selection_proxy:
Image|endswith:
- '\rundll32.exe'
- '\regsvr32.exe'
- '\wmic.exe'
- '\psexec.exe'
- '\powershell.exe'
selection_cli:
CommandLine|contains:
- '\\postex_'
- '\\msagent_'
- '\\status_'
- '/node:'
- 'process call create'
- '-s -d '
- 'IEX '
- 'FromBase64String'
condition: selection_proxy and selection_cli
falsepositives:
- Administrative scripts
- EDR and management agents using remote services
level: high
tags:
- attack.lateral_movement
- attack.execution
- attack.t1021.002
- attack.t1047
- attack.t1059.001
// Sentinel hunt: remote authentication -> suspicious tooling -> backup/ shadow-copy tampering window
let WindowStart = ago(14d);
let RemoteLogons =
SecurityEvent
| where TimeGenerated >= WindowStart
| where EventID == 4624 and LogonType in (3,10)
| where IpAddress !startswith "10." and IpAddress !startswith "192.168." and IpAddress !startswith "172."
| summarize FirstRemote=min(TimeGenerated), RemoteIPs=make_set(IpAddress) by Account, Computer;
let SuspiciousProc =
SecurityEvent
| where TimeGenerated >= WindowStart
| where EventID == 4688
| where NewProcessName has_any ("psexec.exe","wmic.exe","rundll32.exe","regsvr32.exe","powershell.exe","vssadmin.exe","wbadmin.exe","bcdedit.exe","7z.exe","rar.exe")
| extend CommandLine = tostring(parse_xml(EventData).EventData.Data.[?(@Name=='CommandLine')].['#text'])
| where CommandLine has_any ("process call create","delete shadows","resize shadowstorage","wbadmin delete catalog","recoveryenabled no","FromBase64String","Compress-Archive","postex_","msagent_","-s -d ")
| summarize ToolEvents=count(), FirstTool=min(TimeGenerated), Commands=make_set(CommandLine) by Account, Computer;
RemoteLogons
| join kind=inner SuspiciousProc on Account, Computer
| where FirstTool between (FirstRemote .. FirstRemote + 6h)
| project Computer, Account, FirstRemote, RemoteIPs, FirstTool, ToolEvents, Commands
| order by FirstTool asc;
# Rapid exposure sweep for ransomware pre-staging indicators. Run elevated; review before remediation.
$Since = (Get-Date).AddDays(-7)
Write-Host '[*] RDP exposure and listeners'
Get-NetTCPConnection -State Listen -LocalPort 3389 -ErrorAction SilentlyContinue | Select-Object LocalAddress,LocalPort,OwningProcess
Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue | Select-Object fDenyTSConnections
Write-Host '[*] Scheduled tasks created in last 7 days'
Get-ScheduledTask | Where-Object {$_.Date -gt $Since} | Select-Object TaskName,TaskPath,Date,Author | Format-Table -AutoSize
Write-Host '[*] New local admins and suspicious services'
Get-LocalGroupMember -Group 'Administrators' -ErrorAction SilentlyContinue | Select-Object Name,PrincipalSource
Get-CimInstance Win32_Service | Where-Object {$_.CreationDate -gt $Since} | Select-Object Name,PathName,StartName,State,CreationDate | Format-Table -AutoSize
Write-Host '[*] Shadow copy status and recent deletion clues'
vssadmin list shadows
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7036; StartTime=$Since} -ErrorAction SilentlyContinue | Where-Object {$_.Message -match 'Volume Shadow Copy|VSS'} | Select-Object TimeCreated,Message
Write-Host '[*] Recent archive-like artifacts in staging paths'
$Paths = @("$env:ProgramData","$env:PUBLIC","$env:TEMP")
foreach ($p in $Paths) { Get-ChildItem $p -Recurse -ErrorAction SilentlyContinue -Include *.zip,*.rar,*.7z,*.tar,*.gz | Where-Object {$_.LastWriteTime -gt $Since -and $_.Length -gt 100MB} | Select-Object FullName,Length,LastWriteTime }
Incident Response Priorities
T-minus detection checklist, before encryption fires:
- Identity: impossible travel or foreign ASN logins into VPN/RDP/VDI; sudden MFA fatigue prompts; new local/domain admins; disabled EDR via tamper-protection events; Kerberoasting or AS-REP roasting bursts; DCSync-style replication requests.
- Edge: unexplained Check Point/Cisco FMC/VMware vCenter/TeamCity/Nx Console exposure, new admin sessions to management planes, config exports, IKEv1 anomalies, and emergency patch gaps.
- Endpoint/server: rundll32/regsvr32 with encoded commands, WMI process call create to multiple hosts, PsExec-like service installs, Cobalt Strike-style named pipes, archive tools writing to ProgramData/Public/Temp, mass SMB reads followed by staged archives.
- Impact precursors: vssadmin delete shadows, wbadmin delete catalog, bcdedit recoveryenabled no, backup job failures outside maintenance windows, hypervisor snapshot deletion, NAS backup share lockout, security tool service stops.
- Exfil: unusual egress to MEGAsync-like, Rclone, FileZilla, cloud storage, VPS ASNs, or TOR-adjacent infrastructure; sustained upload from file servers, EHR/ pharmacy databases, ERP shares, CAD repositories, build artifacts, and customer databases.
Critical assets this gang's playbook likely prioritizes for leverage, based on claimed sectors and common ransomware economics:
- Healthcare: EHR exports, pharmacy dispensing records, ePHI, billing, payer contracts, identity documents, lab interfaces, downtime procedures, and third-party clinic connectivity.
- Manufacturing/industrial: ERP, MES, CAD/PLM drawings, supplier pricing, OT jump hosts, quality records, shipping schedules, customer lists, and backup repositories.
- Technology/provider: source repositories, build signing keys where present, customer tenant metadata, support remote-access credentials, CI/CD secrets, ticket histories containing passwords, and partner contracts.
Containment actions ordered by urgency:
- Isolate identity and edge first: disable suspect sessions, revoke tokens, force password resets for exposed remote-access admins, block malicious IPs/ASNs at VPN/firewall, and shut down unauthorized RDP/SMB ingress without tipping broad deletion if forensics are needed.
- Protect crown jewels and backups: isolate backup consoles, verify immutable/offline copies, snapshot critical systems if safe, pause suspect backup deletion jobs, and restrict write access to EHR/ERP/CAD shares.
- Segment laterally: deny workstation-to-workstation SMB/RDP/WMI, constrain server-to-server admin paths, isolate hypervisor management and storage networks, and place OT/ICS behind deny-by-default rules.
- Preserve evidence: capture memory on key servers where feasible, export VPN/firewall/EDR/AD logs, record negotiator/leak-site artifacts through lawful channels, and avoid wiping staging directories before triage.
- Engage stakeholders: counsel, insurer, regulator-facing compliance, executive crisis team, MSP/MSSP, law enforcement where appropriate, and communications prepared for claim-driven media pressure.
Hardening Recommendations
Immediate, next 24 hours:
- Inventory and mitigate CISA KEV exposure for CVE-2026-59310 vCenter, CVE-2026-63077 TeamCity, CVE-2026-20316 Cisco Secure FMC, CVE-2026-50751 Check Point IKEv1 improper authentication, and CVE-2026-48027 Nx Console embedded malicious code. Patch, isolate management interfaces, or add compensating controls now; do not assert these CVEs caused any listing absent evidence.
- Disable inbound RDP from the internet, enforce VPN MFA with phishing-resistant methods for admins, block legacy IKEv1 where not required, and geo/ASN restrict remote administration.
- Rotate credentials for VPN, firewall, vCenter, backup, CI/CD, MSP/RMM, service accounts, and any account with recent external logons; revoke stale API keys and tokens.
- Deploy the Sigma/KQL hunts above, alert on shadow-copy deletion and backup catalog tampering, and create high-severity paging for EDR tamper, mass SMB reads, and archive staging.
- Verify offline/immutable backup restore for EHR, pharmacy, ERP, file, CAD, build, and identity systems; test one restore path, not just backup success.
Short-term, within 2 weeks:
- Move management planes for virtualization, firewalls, backups, and CI/CD behind dedicated PAW/jump access with Just Enough Administration, session recording, and no direct internet exposure.
- Enforce tiered administration, LAPS, gMSA where suitable, protected users for domain admins, and conditional access that blocks legacy auth and unmanaged devices.
- Implement application control for rundll32/regsvr32/Office child processes in high-risk departments, constrain PowerShell with logging and constrained language mode for standard users, and disable macros from the internet by default.
- Segment IT/OT and clinical/business networks; deploy egress filtering with TLS inspection where lawful, alert on Rclone/MEGA-like tools and rare cloud destinations, and require DLP review for bulk sensitive data movement.
- Establish leak-site claim runbooks: monitoring, legal/PR decision tree, regulator thresholds, customer notification criteria, and a pre-approved no-ransom/payment governance position before pressure arrives.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.