Incransom is a Ransomware-as-a-Service crime group active since 2023, targeting various sectors globally.
Analyst brief
Incransom (aka Inc Ransom, GOLD IONIC) is a prolific ransomware-as-a-service crime group active since July 2023, systematically targeting sectors like Healthcare, Government, Education, and Manufacturing across North and South America, Europe, and Asia-Pacific. They commonly gain initial access via Exploit Public-Facing Application and Phishing, then move laterally using RDP, PsExec, and Nltest, while leveraging tools like Rclone for data exfiltration to cloud accounts before deploying INC Ransomware for encryption. Defenders should focus on patching public-facing vulnerabilities, enforcing strong network segmentation, and closely monitoring for anomalous RDP sessions and the use of tools like Rclone and AdFind for data staging and discovery.
incransom
Inc RansomGOLD IONIC
activecrime
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.
observed victims (by country)
United StatesBrazilUnited KingdomCanada
observed sectors
Professional ServicesManufacturingHealthcareTechnology