Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Rust-Based Ransomware Threatens Global Industries

Rust-Based Ransomware Threatens Global Industries

Posted on June 19, 2026 By CWS

The INC ransomware group has rapidly escalated into a major global threat since its emergence in mid-2023. Within a short span, the group has victimized over 800 entities, placing it prominently among the top ransomware threats of the year. Operating under a Ransomware-as-a-Service (RaaS) model, INC recruits affiliates and equips them with sophisticated tools to execute widespread attacks.

Strategic Evolution and Target Expansion

INC’s threat capability has grown through continuous technical enhancements, making it difficult for security measures to detect. Initially focusing on healthcare and education, the group has broadened its reach to include legal firms, manufacturing, construction, and tech companies. This strategic shift indicates a focus on sectors vulnerable to regulatory pressure, increasing the likelihood of ransom payments.

Recent analyses by Acronis reveal significant advancements in INC’s toolkit and infrastructure. Their report, shared with Cyber Security News (CSN), highlights the group’s complete rewrite of Windows and Linux/ESXi encryptors using Rust. This development underscores a commitment to cross-platform attack strategies, enhancing the group’s operational adaptability.

Technical Advancements and Implications

The shift to Rust-based encryptors is a pivotal development, allowing the group to maintain a singular codebase while targeting diverse system environments. Rust complicates analysis due to its complex structural patterns, challenging older security tools.

Improvements in INC’s Windows encryptor include automated database connection retrieval and a zero SQL server for targeting Veeam backup systems. The Linux/ESXi variant efficiently targets VMware setups, optimizing encryption speed by distinguishing between local and network storage.

Both encryptors employ partial encryption based on file size, expediting the process while ensuring critical system files remain intact, thus keeping ransom notes visible. Command-line configurability grants affiliates precise control over each attack.

Operational Tactics and Security Recommendations

Beyond encryption tools, INC affiliates utilize legitimate remote access software and commercial tools to navigate victim networks stealthily. Tools such as CobaltStrike, AnyDesk, and TeamViewer blend with normal IT activities to evade detection. Additionally, scripts and utilities like PsKill are employed to disable endpoint defenses before final payload deployment.

For credential theft, INC leverages modified scripts to bypass newer Veeam backups’ security. Compressed stolen data is exfiltrated using tools like rclone. Security teams are advised to enforce multi-factor authentication, patch known vulnerabilities, and maintain isolated offline backups.

The spread of INC’s source code into other ransomware families like Lynx and Knoba suggests a persistent threat landscape, despite disruptions in the original code seller’s operations. Continuous vigilance and adaptive security measures remain crucial for organizations to mitigate the impact of such sophisticated attacks.

Follow our updates on Google News, LinkedIn, and X, and set CSN as your preferred source on Google for real-time cybersecurity news.

Cyber Security News Tags:credential theft, cross-platform, cyber attacks, cyber threat, Cybersecurity, data breach, data protection, Encryption, INC group, Linux, Ransomware, Rust, Security, Technology, Windows

Post navigation

Previous Post: Unpatchable usbliter8 Exploit Affects Apple Devices
Next Post: Gentlemen RaaS Targets Security with EDR Framework

Related Posts

Hackers Exploit Shopify’s Shop App with Phony Invoices Hackers Exploit Shopify’s Shop App with Phony Invoices Cyber Security News
Google Now Allows Users to Change Their @gmail.com Email Address Google Now Allows Users to Change Their @gmail.com Email Address Cyber Security News
Hackers Exploit Fake Deals to Steal Corporate Funds Hackers Exploit Fake Deals to Steal Corporate Funds Cyber Security News
Critical Windows Netlogon RCE Exploited in the Wild Critical Windows Netlogon RCE Exploited in the Wild Cyber Security News
Global Mobile Networks Exploited by Hackers via SS7 and Diameter Global Mobile Networks Exploited by Hackers via SS7 and Diameter Cyber Security News
New BRICKSTORM Stealthy Backdoor Attacking Tech and Legal Sectors New BRICKSTORM Stealthy Backdoor Attacking Tech and Legal Sectors Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities
  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities
  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark