Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Rust-Based Ransomware Threatens Global Industries

Rust-Based Ransomware Threatens Global Industries

Posted on June 19, 2026 By CWS

The INC ransomware group has rapidly escalated into a major global threat since its emergence in mid-2023. Within a short span, the group has victimized over 800 entities, placing it prominently among the top ransomware threats of the year. Operating under a Ransomware-as-a-Service (RaaS) model, INC recruits affiliates and equips them with sophisticated tools to execute widespread attacks.

Strategic Evolution and Target Expansion

INC’s threat capability has grown through continuous technical enhancements, making it difficult for security measures to detect. Initially focusing on healthcare and education, the group has broadened its reach to include legal firms, manufacturing, construction, and tech companies. This strategic shift indicates a focus on sectors vulnerable to regulatory pressure, increasing the likelihood of ransom payments.

Recent analyses by Acronis reveal significant advancements in INC’s toolkit and infrastructure. Their report, shared with Cyber Security News (CSN), highlights the group’s complete rewrite of Windows and Linux/ESXi encryptors using Rust. This development underscores a commitment to cross-platform attack strategies, enhancing the group’s operational adaptability.

Technical Advancements and Implications

The shift to Rust-based encryptors is a pivotal development, allowing the group to maintain a singular codebase while targeting diverse system environments. Rust complicates analysis due to its complex structural patterns, challenging older security tools.

Improvements in INC’s Windows encryptor include automated database connection retrieval and a zero SQL server for targeting Veeam backup systems. The Linux/ESXi variant efficiently targets VMware setups, optimizing encryption speed by distinguishing between local and network storage.

Both encryptors employ partial encryption based on file size, expediting the process while ensuring critical system files remain intact, thus keeping ransom notes visible. Command-line configurability grants affiliates precise control over each attack.

Operational Tactics and Security Recommendations

Beyond encryption tools, INC affiliates utilize legitimate remote access software and commercial tools to navigate victim networks stealthily. Tools such as CobaltStrike, AnyDesk, and TeamViewer blend with normal IT activities to evade detection. Additionally, scripts and utilities like PsKill are employed to disable endpoint defenses before final payload deployment.

For credential theft, INC leverages modified scripts to bypass newer Veeam backups’ security. Compressed stolen data is exfiltrated using tools like rclone. Security teams are advised to enforce multi-factor authentication, patch known vulnerabilities, and maintain isolated offline backups.

The spread of INC’s source code into other ransomware families like Lynx and Knoba suggests a persistent threat landscape, despite disruptions in the original code seller’s operations. Continuous vigilance and adaptive security measures remain crucial for organizations to mitigate the impact of such sophisticated attacks.

Follow our updates on Google News, LinkedIn, and X, and set CSN as your preferred source on Google for real-time cybersecurity news.

Cyber Security News Tags:credential theft, cross-platform, cyber attacks, cyber threat, Cybersecurity, data breach, data protection, Encryption, INC group, Linux, Ransomware, Rust, Security, Technology, Windows

Post navigation

Previous Post: Unpatchable usbliter8 Exploit Affects Apple Devices
Next Post: Gentlemen RaaS Targets Security with EDR Framework

Related Posts

INE Expands Cross-Skilling Innovations INE Expands Cross-Skilling Innovations Cyber Security News
Threat Actors Using Multilingual ZIP File to Attack Financial and Goverment Organizations Threat Actors Using Multilingual ZIP File to Attack Financial and Goverment Organizations Cyber Security News
Hackers Exploit AI to Hijack Instagram Accounts Hackers Exploit AI to Hijack Instagram Accounts Cyber Security News
SEO Campaign Disguises Apps to Spread AsyncRAT SEO Campaign Disguises Apps to Spread AsyncRAT Cyber Security News
Hackers Reportedly Demand Google Fire Two Employees, Threaten Data Leak Hackers Reportedly Demand Google Fire Two Employees, Threaten Data Leak Cyber Security News
CISA Releases Four ICS Advisories Surrounding Vulnerabilities, and Exploits CISA Releases Four ICS Advisories Surrounding Vulnerabilities, and Exploits Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework
  • Rust-Based Ransomware Threatens Global Industries
  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework
  • Rust-Based Ransomware Threatens Global Industries
  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark