{"id":1166,"date":"2026-08-20T10:58:10","date_gmt":"2026-08-20T05:28:10","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1166"},"modified":"2026-08-20T11:00:36","modified_gmt":"2026-08-20T05:30:36","slug":"inc-ransomware-raas-rust-veeam-credential-theft","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/","title":{"rendered":"INC Ransomware Emerges as a Major RaaS Threat in 2026"},"content":{"rendered":"<p>INC ransomware has rapidly emerged as one of the most active ransomware-as-a-service (RaaS) operations, demonstrating how modern threat groups continue to scale attacks through proven enterprise weaknesses rather than novel exploits alone. Its affiliates combine exposed edge infrastructure, stolen credentials, legitimate remote administration tools, and Rust-based ransomware encryptors to compromise Windows, Linux, and virtualized environments with increasing efficiency.<\/p>\n<p>For enterprise security teams, INC&#8217;s growing activity reinforces a familiar reality: ransomware operators are succeeding by chaining together common security gaps across identity, endpoint, backup, and remote access infrastructure. As the group&#8217;s tactics continue to evolve, organizations need to strengthen detection, reduce attack surface exposure, and improve resilience against increasingly coordinated ransomware campaigns.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-UEM-An-inside-look_infographics-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode-UEM-An-inside-look_infographics\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-UEM-An-inside-look_infographics-1.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-UEM-An-inside-look_infographics-1-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-UEM-An-inside-look_infographics-1-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-UEM-An-inside-look_infographics-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Hexnode-UEM-An-inside-look_infographics\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode UEM: An inside look\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Look at how Hexnode UEM helps IT admins to manage and secure their corporate mobile devices.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/hexnode-an-inside-look\/'>\n                            Get the infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How INC Ransomware Executes Enterprise Attacks<\/h2>\n<p>Rather than relying on a single intrusion technique, INC affiliates combine multiple access vectors to maximize their chances of compromising enterprise environments. Initial access commonly begins through spear-phishing campaigns, credentials purchased from initial access brokers (IABs), or the exploitation of internet-facing applications, including vulnerabilities affecting platforms such as Citrix, Fortinet, and SimpleHelp.<\/p>\n<p>Once inside the network, the attackers establish persistence and expand their foothold using a combination of credential theft and legitimate administrative tools. Observed activity includes:<\/p>\n<ul>\n<li>Credential dumping to obtain privileged accounts.<\/li>\n<li>Lateral movement using RDP and PsExec.<\/li>\n<li>Deployment of Cobalt Strike and legitimate remote management tools to maintain access and execute commands.<\/li>\n<li>Bring Your Own Vulnerable Driver (BYOVD) techniques to disable or bypass endpoint security controls.<\/li>\n<li>Staging sensitive data into password-protected archives before exfiltrating it with Rclone.<\/li>\n<li>Encrypting Windows systems as well as Linux and VMware ESXi environments to maximize operational disruption.<\/li>\n<\/ul>\n<p>Researchers also report that INC has rewritten its Windows and Linux\/ESXi encryptors in Rust. Beyond enabling a more maintainable cross-platform codebase, Rust-compiled binaries can increase the complexity of static analysis and reverse engineering, making malware analysis and detection more challenging for defenders.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Ransomware-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How to protect your business from ransomware<\/h4><p>Protect your business from ransomware with proven security practices, endpoint management & employee awareness.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/protect-business-from-ransomware\/\" aria-label=\"How to protect your business from ransomware\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Reducing INC Ransomware Risk with Hexnode<\/h2>\n<p>The tactics employed by INC ransomware span the endpoint, identity, and infrastructure layers, making continuous visibility and centralized endpoint management essential for early detection and containment.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> can help security teams identify malicious activity associated with the INC attack chain, including:<\/p>\n<ul>\n<li>Credential dumping and attempts to harvest privileged credentials.<\/li>\n<li>Abuse of remote administration tools and suspicious remote access activity.<\/li>\n<li>Suspicious driver loading, including indicators associated with BYOVD techniques.<\/li>\n<li>Lateral movement using administrative utilities such as RDP and PsExec.<\/li>\n<li>Behavioral indicators consistent with ransomware encryption.<\/li>\n<\/ul>\n<p>Complementing threat detection, <a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> can help strengthen an organization&#8217;s security posture by enabling administrators to:<\/p>\n<ul>\n<li>Enforce patch compliance to reduce exposure to known vulnerabilities.<\/li>\n<li>Apply endpoint hardening policies across managed devices.<\/li>\n<li>Restrict unauthorized software through application control.<\/li>\n<li>Support remote remediation and policy enforcement across Windows, Linux, macOS, and mobile devices from a centralized management console.<\/li>\n<\/ul>\n<h2>Key Takeaways for Enterprise Security Teams<\/h2>\n<p>INC&#8217;s rapid growth demonstrates that successful ransomware campaigns continue to capitalize on exposed internet-facing systems, compromised credentials, accessible backup infrastructure, and techniques designed to evade endpoint defenses. Rather than relying solely on zero-day exploits, many affiliates chain together well-known weaknesses to achieve enterprise-wide impact.<\/p>\n<p>To reduce risk, security teams should prioritize:<\/p>\n<ul>\n<li>Minimizing the external attack surface by patching and securing internet-facing applications.<\/li>\n<li>Enforcing strong identity controls, including phishing-resistant MFA and least-privilege access.<\/li>\n<li>Continuously monitoring and protecting backup infrastructure, ensuring backup credentials and repositories are isolated from production environments.<\/li>\n<li>Detecting lateral movement, credential theft, and suspicious remote administration activity as early as possible.<\/li>\n<li>Establishing rapid containment procedures that can isolate compromised systems before attackers progress from initial access to data exfiltration and ransomware deployment.<\/li>\n<\/ul>\n<p>For defenders, the lesson is clear: reducing attack paths and accelerating detection and containment remain the most effective ways to disrupt modern ransomware operations before encryption begins.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f <\/h5><p>Reduce ransomware risk with centralized endpoint security and management. Try Hexnode free today.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>INC ransomware has rapidly emerged as one of the most active ransomware-as-a-service (RaaS) operations, demonstrating&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1167,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[11,13],"class_list":["post-1166","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","category-identity-abuse","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>INC Ransomware Emerges as a Major RaaS Threat in 2026<\/title>\n<meta name=\"description\" content=\"INC ransomware has claimed 830+ victims, using Rust encryptors, Veeam credential theft, edge exploits and RMM tools.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"INC Ransomware Emerges as a Major RaaS Threat in 2026\" \/>\n<meta property=\"og:description\" content=\"INC ransomware has claimed 830+ victims, using Rust encryptors, Veeam credential theft, edge exploits and RMM tools.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-20T05:28:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-20T05:30:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/INC-ransomware.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"INC Ransomware Emerges as a Major RaaS Threat in 2026\",\"datePublished\":\"2026-08-20T05:28:10+00:00\",\"dateModified\":\"2026-08-20T05:30:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/\"},\"wordCount\":625,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/INC-ransomware.webp?format=webp\",\"articleSection\":[\"Ransomware\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/\",\"name\":\"INC Ransomware Emerges as a Major RaaS Threat in 2026\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/INC-ransomware.webp?format=webp\",\"datePublished\":\"2026-08-20T05:28:10+00:00\",\"dateModified\":\"2026-08-20T05:30:36+00:00\",\"description\":\"INC ransomware has claimed 830+ victims, using Rust encryptors, Veeam credential theft, edge exploits and RMM tools.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/INC-ransomware.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/INC-ransomware.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"INC-ransomware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inc-ransomware-raas-rust-veeam-credential-theft\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"INC Ransomware Emerges as a Major RaaS Threat in 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"INC Ransomware Emerges as a Major RaaS Threat in 2026","description":"INC ransomware has claimed 830+ victims, using Rust encryptors, Veeam credential theft, edge exploits and RMM tools.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/","og_locale":"en_US","og_type":"article","og_title":"INC Ransomware Emerges as a Major RaaS Threat in 2026","og_description":"INC ransomware has claimed 830+ victims, using Rust encryptors, Veeam credential theft, edge exploits and RMM tools.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-20T05:28:10+00:00","article_modified_time":"2026-08-20T05:30:36+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/INC-ransomware.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"INC Ransomware Emerges as a Major RaaS Threat in 2026","datePublished":"2026-08-20T05:28:10+00:00","dateModified":"2026-08-20T05:30:36+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/"},"wordCount":625,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/INC-ransomware.webp?format=webp","articleSection":["Ransomware","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/","url":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/","name":"INC Ransomware Emerges as a Major RaaS Threat in 2026","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/INC-ransomware.webp?format=webp","datePublished":"2026-08-20T05:28:10+00:00","dateModified":"2026-08-20T05:30:36+00:00","description":"INC ransomware has claimed 830+ victims, using Rust encryptors, Veeam credential theft, edge exploits and RMM tools.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/INC-ransomware.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/INC-ransomware.webp?format=webp","width":1024,"height":535,"caption":"INC-ransomware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/inc-ransomware-raas-rust-veeam-credential-theft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"INC Ransomware Emerges as a Major RaaS Threat in 2026"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1166"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1166\/revisions"}],"predecessor-version":[{"id":1171,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1166\/revisions\/1171"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1167"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}