Back to Intelligence

INCRANSOM Ransomware Gang: 5 New Leak-Site Listings Across Education, Manufacturing & Transportation — Unverified Claims, Detection Rules & Hunting Queries

SA
Security Arsenal Team
October 8, 2026
13 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-08 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

INCRANSOM Ransomware Gang: 5 New Leak-Site Listings Across Education, Manufacturing & Transportation

Executive Summary

INCRANSOM's dark web leak site shows five new listings published between 2026-10-06 and 2026-10-07, spanning education, professional services, transportation, manufacturing, and one uncategorized organization. The claimed victims are concentrated in the United States (4 of 5) with one German professional services firm. Critically, all five listings are single-source observations — a second independent leak-site crawler has not corroborated that these postings exist, and no tier of this data confirms any breach occurred. These are accusations by a criminal enterprise, nothing more.

That said, unverified leak-site claims are still actionable defensive intelligence. Organizations in the education, manufacturing, and transportation sectors — particularly mid-market US firms with exposed remote access infrastructure — should treat this cluster as a prompt to hunt for INCRANSOM's known pre-encryption TTPs, review KEV-listed perimeter exposure, and validate exfiltration detection coverage.

Sourcing & Verification

  • 0 of 5 listings were independently observed by a second leak-site crawler. 5 of 5 appear on a single source only (ransomware.live). Single-source means one crawler saw the gang post the claim; it does not mean the posting was corroborated, and it categorically does not mean a breach is confirmed.
  • Inclusion in this briefing reflects the threat actor's claim and is not confirmation of a breach. Only the named organization or its regulator can confirm whether an incident occurred.
  • A named organization may dispute the listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable — so neither silence nor denial settles the question.
  • Security Arsenal will publish corrections to this briefing and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — INCRANSOM

INCRANSOM (tracked in open reporting as INC Ransom) is a ransomware operation that emerged in mid-2023 and has maintained consistent leak-site activity since. Key characteristics relevant to defenders:

  • Operating model: Functions as a semi-closed ransomware operation with characteristics of a RaaS program — a core operator team with a limited set of vetted affiliates rather than an open marketplace model. This produces more consistent TTPs across intrusions than high-volume RaaS brands.
  • Aliases / overlaps: INC Ransom, INC Ransomware. Intrusion tradecraft overlaps with tooling commonly seen from initial access brokers (IABs), suggesting the group frequently buys access rather than developing bespoke initial access.
  • Ransom demands: Typically scaled to victim revenue; demands reported in the low-to-mid six figures for SMB targets, escalating into seven figures for larger organizations. Negotiation is conducted via a TOR-hosted victim portal.
  • Initial access methods (historical): Valid credentials purchased from IABs, exploitation of internet-facing remote access services (VPN concentrators, RDP gateways, firewall management interfaces), spear-phishing with macro- or script-based loaders, and opportunistic exploitation of perimeter appliances. Known to leverage legitimate remote management tools (AnyDesk, Atera-style RMM) for persistence.
  • Double extortion: Yes — data theft precedes encryption in most observed intrusions. The gang's leak site is used to publish victim names, countdown timers, and staged sample data to pressure payment.
  • Dwell time: Observed dwell time before detonation is typically short-to-moderate — on the order of days rather than weeks. This compresses the defender's window: pre-encryption staging behaviors (discovery, credential dumping, exfil staging) are the highest-value detection surface.
  • Encryption behavior: Rapid encryption of accessible network shares and hypervisor datastores where reachable; partial encryption techniques to speed detonation. Volume Shadow Copy deletion via vssadmin/wmic is standard.

Current Campaign Analysis

Claimed listings (all single-source, unverified)

OrganizationSectorCountryPublishedCorroboration
The New Community SchoolEducationUS2026-10-07SINGLE-SOURCE
architekt-vondanwitz.deProfessional ServicesDE2026-10-06SINGLE-SOURCE
harborpacific.comTransportationUS2026-10-06SINGLE-SOURCE
acmestamping.comManufacturingUS2026-10-06SINGLE-SOURCE
magnals.comOtherUS2026-10-06SINGLE-SOURCE

Sector targeting

The cluster is spread across five sectors with no single dominant vertical — consistent with INCRANSOM's historical opportunistic posture (access-driven victimology rather than vertical campaigns). However, the presence of a K-12/private education institution and a manufacturer aligns with the group's demonstrated appetite for organizations with (a) constrained security budgets, (b) operational technology or uptime sensitivity that increases payment pressure, and (c) often-flat internal networks.

Geographic concentration

4 of 5 claimed victims are US-based; 1 is German. This matches INCRANSOM's known focus on North American and Western European mid-market targets — jurisdictions where ransom payment capacity exists but regulatory ransom-payment prohibitions are not (yet) absolute blockers for the gang's business model.

Victim profile

The named organizations are predominantly small-to-mid-market firms — estimated revenue bands roughly $5M–$100M based on sector norms for single-domain regional businesses of these types. This is classic INCRANSOM territory: large enough to pay, small enough to lack a 24/7 SOC.

Posting cadence

Five listings in a 48-hour window (2026-10-06 → 2026-10-07) represents a batch drop. Batch postings often indicate either (a) a backlog of completed intrusions published together for pressure effect, or (b) a single IAB-supplied access wave against similarly-hardened perimeter stacks. With single-source-only corroboration, treat the batch itself as lower-confidence than a multi-source cluster.

CVE exposure — hypothesis, not attribution

We have no evidence linking any specific named listing above to any specific CVE. What we can say at the sector level: INCRANSOM's known playbook favors perimeter and remote-access exploitation, and the following actively exploited vulnerabilities (all on CISA's KEV with confirmed ransomware use) map directly onto that access model. Any organization in the targeted sectors running these products should assume attempted exploitation:

  • CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Direct VPN gateway compromise — the single most consistent initial access pattern for this class of actor. Patch and audit VPN accounts now.
  • CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane compromise of the perimeter; treat FMC exposure to untrusted networks as an emergency.
  • CVE-2026-59310 — VMware vCenter path traversal. Hypervisor-layer access aligns with INCRANSOM's observed interest in datastore-level encryption for maximum impact.
  • CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise enables supply-chain-style lateral movement and code-signing abuse.
  • CVE-2026-48027 — Nx Console embedded malicious code. Developer-workstation supply chain vector; relevant to professional services firms with dev shops.

Priority: if you run Check Point gateways or Cisco FMC with any internet-facing management surface, treat KEV remediation as a 24-hour action.

Detection Engineering

The following detections target INCRANSOM's documented TTP chain: perimeter/VPN access → discovery → credential access → lateral movement (PsExec/WMI/RMM) → exfil staging → shadow copy deletion → encryption.

YAML
---
title: INCRANSOM - Volume Shadow Copy Deletion Pre-Ransomware
id: 7f3a1c2e-1a01-4b3c-9d01-incransom00001
status: production
description: Detects deletion or resizing of Volume Shadow Copies via vssadmin, wmic, bcdedit, or PowerShell — a near-universal pre-encryption step in INCRANSOM intrusions.
author: Security Arsenal Threat Intelligence
references:
  - https://securityarsenal.com/darkside
date: 2026/10/08
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
  selection_cmd:
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
      - 'resize shadowstorage'
      - 'recoveryenabled no'
      - 'Delete shadows /all'
      - 'Win32_ShadowCopy'
  condition: selection_img and selection_cmd
falsepositives:
  - Legitimate backup software maintenance (rare; validate against backup windows)
level: high
tags:
  - attack.impact
  - attack.t1490
---
title: INCRANSOM - PsExec or Remote Service Creation for Lateral Movement
id: 7f3a1c2e-1a01-4b3c-9d01-incransom00002
status: production
description: Detects remote service creation patterns consistent with PsExec-style lateral movement and Cobalt Strike service execution used in INCRANSOM intrusions.
author: Security Arsenal Threat Intelligence
references:
  - https://securityarsenal.com/darkside
date: 2026/10/08
logsource:
  product: windows
  service: system
detection:
  selection_event:
    EventID: 7045
  selection_service:
    ServiceName|contains:
      - 'PSEXESVC'
      - 'PAExec'
      - 'csexec'
    ImagePath|contains:
      - 'ADMIN$'
      - '\\%SYSTEMROOT%\\'
      - '%COMSPEC%'
  condition: selection_event and selection_service
falsepositives:
  - Legitimate administrative tooling — baseline admin PsExec usage per host
level: high
tags:
  - attack.lateral_movement
  - attack.t1569.002
  - attack.t1021.002
---
title: INCRANSOM - Data Staging and Exfiltration via Archiving or Rclone
id: 7f3a1c2e-1a01-4b3c-9d01-incransom00003
status: production
description: Detects mass archive creation and cloud exfiltration tooling (rclone, 7z/WinRAR with password flags) consistent with INCRANSOM double-extortion staging before encryption.
author: Security Arsenal Threat Intelligence
references:
  - https://securityarsenal.com/darkside
date: 2026/10/08
logsource:
  category: process_creation
  product: windows
detection:
  selection_rclone:
    Image|endswith: '\rclone.exe'
    CommandLine|contains:
      - 'copy'
      - 'sync'
      - 'move'
      - '--config'
      - 'mega'
      - 'dropbox'
      - 's3'
  selection_archive:
    Image|endswith:
      - '\7z.exe'
      - '\7za.exe'
      - '\rar.exe'
      - '\winrar.exe'
    CommandLine|contains:
      - ' -p'
      - ' -hp'
      - ' a '
  condition: selection_rclone or selection_archive
falsepositives:
  - Legitimate backup/archival jobs — correlate with service accounts and scheduled tasks
level: medium
tags:
  - attack.collection
  - attack.t1560.001
  - attack.exfiltration
  - attack.t1567.002

The KQL query below hunts the compressed-dwell-time kill chain in Microsoft Sentinel/Defender: it surfaces hosts where discovery, credential access, shadow copy tampering, or suspicious remote execution occur within a rolling window — the exact pre-encryption signal set for this actor.

KQL — Microsoft Sentinel / Defender
// INCRANSOM pre-encryption hunt: discovery + shadow copy tampering + remote exec co-occurrence
let lookback = 7d;
let suspiciousProc = dynamic(["vssadmin.exe","wmic.exe","bcdedit.exe","psexec.exe","psexesvc.exe","rclone.exe","nltest.exe","net.exe","adfind.exe","anydesk.exe"];
let procEvents =
    DeviceProcessEvents
    | where TimeGenerated >= ago(lookback)
    | where FileName in~ (suspiciousProc)
    | extend Indicator = case(
        ProcessCommandLine has_any ("delete shadows","shadowcopy","recoveryenabled no"), "ShadowCopyTamper",
        FileName =~ "psexec.exe" or FileName =~ "psexesvc.exe", "PsExec",
        FileName =~ "rclone.exe", "ExfilTool",
        FileName =~ "adfind.exe" or ProcessCommandLine has "nltest", "DomainDiscovery",
        ProcessCommandLine has_any ("net group","net user /domain","net localgroup administrators"), "AccountDiscovery",
        FileName =~ "anydesk.exe", "UnsanctionedRMM",
        "Other");
procEvents
| summarize IndicatorSet = make_set(Indicator), Commands = make_set(ProcessCommandLine, 10), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), Count = count() by DeviceName, AccountName, bin(TimeGenerated, 1d)
| where array_length(IndicatorSet) >= 2  // co-occurrence of 2+ pre-ransom behaviors on same host/day
| extend RiskScore = array_length(IndicatorSet) * 20 + Count
| order by RiskScore desc;

The following PowerShell rapid-triage script checks a host (or list of hosts) for the highest-signal INCRANSOM pre-encryption artifacts: recently created scheduled tasks, shadow copy state, RDP exposure, and unsigned executables dropped in user-writable directories in the last 7 days.

PowerShell
# INCRANSOM Rapid Triage — run elevated; targets pre-encryption artifacts
param(
    [string[]]$Computers = @($env:COMPUTERNAME),
    [int]$DaysBack = 7
)
$cutoff = (Get-Date).AddDays(-$DaysBack)

foreach ($c in $Computers) {
    Write-Host "`n===== $c =====" -ForegroundColor Cyan
    Invoke-Command -ComputerName $c -ScriptBlock {
        param($cutoff)

        Write-Host "[1] Scheduled tasks created in last $(([datetime]::Now - $cutoff).Days) days:" -ForegroundColor Yellow
        Get-ScheduledTask | ForEach-Object {
            $info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
            $xml = Export-ScheduledTask -TaskName $_.TaskName -TaskPath $_.TaskPath -ErrorAction SilentlyContinue
            if ($xml -match '<Date>([^<]+)</Date>') {
                $created = [datetime]$Matches[1]
                if ($created -gt $cutoff) {
                    [PSCustomObject]@{ Task = "$($_.TaskPath)$($_.TaskName)"; Created = $created; Author = $_.Author }
                }
            }
        } | Format-Table -AutoSize

        Write-Host "[2] Volume Shadow Copies (should normally exist):" -ForegroundColor Yellow
        $shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
        if (-not $shadows) { Write-Host "  *** NO SHADOW COPIES FOUND — investigate deletion ***" -ForegroundColor Red }
        else { $shadows | Select-Object InstallDate, DeviceObject | Format-Table -AutoSize }

        Write-Host "[3] RDP exposure:" -ForegroundColor Yellow
        $rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
        $nla = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue
        [PSCustomObject]@{
            RdpEnabled = ($rdp.fDenyTSConnections -eq 0)
            NlaEnabled = ($nla.UserAuthentication -eq 1)
            Port       = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -ErrorAction SilentlyContinue).PortNumber
        } | Format-List

        Write-Host "[4] Unsigned executables in user-writable paths (last $(([datetime]::Now - $cutoff).Days) days):" -ForegroundColor Yellow
        $paths = @("$env:PUBLIC", "$env:TEMP", "$env:ProgramData", "$env:APPDATA")
        foreach ($p in $paths) {
            if (Test-Path $p) {
                Get-ChildItem $p -Recurse -Include *.exe,*.dll -ErrorAction SilentlyContinue |
                    Where-Object { $_.LastWriteTime -gt $cutoff } |
                    ForEach-Object {
                        $sig = Get-AuthenticodeSignature $_.FullName
                        if ($sig.Status -ne 'Valid') {
                            [PSCustomObject]@{ Path = $_.FullName; Modified = $_.LastWriteTime; SigStatus = $sig.Status }
                        }
                    }
            }
        } | Format-Table -AutoSize
    } -ArgumentList $cutoff -ErrorAction SilentlyContinue
}

Incident Response Priorities

T-minus detection checklist (before encryption fires)

INCRANSOM's compressed dwell time means these signals may appear only 24–72 hours before detonation:

  1. Shadow copy tampering — vssadmin delete shadows, bcdedit ... recoveryenabled no, WMI Win32_ShadowCopy deletion. This is often the final pre-encryption step. Alert at CRITICAL.
  2. New RMM tooling — AnyDesk, Atera, Splashtop, or similar installed on servers where IT did not deploy it. INCRANSOM affiliates lean on legitimate RMM for persistence and lateral movement.
  3. Mass archive creation — 7z/RAR with password flags against file shares, or rclone configs appearing on file servers. Double extortion means exfil precedes encryption; catching staging catches the incident.
  4. Domain-wide discovery bursts — nltest /dclist, net group "Domain Admins" /domain, AdFind executions from non-admin workstations.
  5. Credential dumping artifacts — LSASS access by non-system processes, comsvcs.dll MiniDump usage, NTDS.dit access on domain controllers.
  6. VPN/firewall authentication anomalies — logins from unusual geographies/ASNs against Check Point or Cisco-managed perimeter devices, especially accounts lacking MFA.

Assets this gang prioritizes for exfiltration

  • File servers hosting HR, finance, and legal data (PII drives extortion leverage)
  • Email archives of executives and legal counsel
  • Backup infrastructure credentials and catalogs (to destroy recovery options)
  • Domain controllers (NTDS.dit) for full-domain credential theft
  • For manufacturing victims: engineering drawings and ERP data; for education: student records (FERPA-regulated PII increases pressure)

Containment actions — ordered by urgency

  1. Isolate, don't power off — network-quarantine suspected hosts (EDR isolate or switch-port shutdown) to preserve volatile memory and staging evidence.
  2. Disable compromised and suspicious accounts — force-reset any account seen in discovery/lateral-movement telemetry; revoke VPN sessions globally.
  3. Block exfil paths at the egress — deny rclone-associated cloud endpoints and non-business file-sharing domains at the proxy/firewall.
  4. Protect backups immediately — take backup management interfaces offline, verify immutable/offline copies exist, rotate backup service credentials.
  5. Audit perimeter appliances — check Check Point / Cisco FMC logs for exploitation indicators matching KEV CVEs above; assume credential theft if exploitation is suspected.
  6. Engage IR retainer early — INCRANSOM's short dwell time punishes delayed escalation.

Hardening Recommendations

Immediate (24 hours)

  • Patch KEV perimeter CVEs — CVE-2026-50751 (Check Point) and CVE-2026-20316 (Cisco FMC) first; remove management interfaces from internet reachability entirely.
  • Enforce phishing-resistant MFA on all VPN, RDP gateway, and remote access paths; disable legacy IKEv1 remote access where feasible.
  • Block or application-allowlist RMM tools — if your org doesn't use AnyDesk/Atera, block them at the endpoint and proxy.
  • Deploy the Sigma and KQL detections above; specifically alert on shadow copy deletion as a paging event.
  • Verify backup immutability and test one restore today.

Short-term (2 weeks)

  • Segment the network — isolate file servers, backup infrastructure, and (for manufacturers) OT-adjacent systems from general user VLANs; require jump-host access with MFA for server administration.
  • Deploy LSA protection and Credential Guard; restrict LSASS access alerting to feed the SOC.
  • Egress filtering by default — deny outbound connections to unsanctioned cloud storage and anonymization services; log everything else.
  • Tiered administration model — separate DA credentials from workstation use; INCRANSOM's lateral movement depends on reusable privileged credentials.
  • vCenter hardening (CVE-2026-59310) — patch, restrict vCenter access to management networks, and enable datastore-level encryption monitoring, since hypervisor encryption is a hallmark endgame.
  • Tabletop the 72-hour scenario — rehearse a no-warning encryption event with stakeholders; INCRANSOM's dwell time leaves no room for ad-hoc decision-making.

This briefing is based on unverified threat-actor claims observed on criminal infrastructure. Security Arsenal will update or correct this analysis as corroborating information becomes available. Named organizations are invited to contact security@securityarsenal.com.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.

INCRANSOM Ransomware Gang: 5 New Leak-Site Listings Across Education, Manufacturing & Transportation — Unverified Claims, Detection Rules & Hunting Queries | Security Arsenal | Security Arsenal