INC RANSOM
CITRIX BLEED
CVE-2023-4966
HEALTHCARE
Threat IntelligenceRansomwareMarch 1, 202611 min read

INC Ransom: Threat Intelligence Profile

Ransomware-as-a-Service operation targeting healthcare, education, and government sectors, known for Citrix Bleed (CVE-2023-4966) exploitation and methodical data exfiltration.

Scroll

INC Ransom is a Ransomware-as-a-Service operation active since July 2023. The group gained notoriety for aggressively targeting healthcare, education, and government organizations, frequently leveraging the Citrix Bleed vulnerability (CVE-2023-4966) for initial access. INC Ransom operates a double extortion model with a sophisticated data leak site.

Overview & Attribution

INC Ransom appeared in July 2023 and quickly established itself as a persistent threat to critical sectors. The group's operations are characterized by methodical reconnaissance and data exfiltration before encryption deployment. INC Ransom gained significant attention for its exploitation of the Citrix Bleed vulnerability (CVE-2023-4966), which allowed session hijacking of Citrix NetScaler appliances. The group has shown willingness to target healthcare organizations, including hospitals actively providing patient care.

Threat Assessment

INC Ransom has been active since July 2023, targeting critical sectors with particular focus on healthcare. The group's exploitation of Citrix Bleed (CVE-2023-4966) enabled mass compromise of organizations using vulnerable Citrix NetScaler ADC and Gateway appliances, leading to dozens of confirmed victims in late 2023 and early 2024.

Arsenal & Tools

INC Ransom employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

INC Ransom aggressively targets healthcare, education, government, technology, and manufacturing organizations. The group has shown a particular willingness to target hospitals and healthcare providers, and has been linked to attacks on public school districts and municipal governments.

Operational Pattern

INC Ransom operations follow a methodical approach: initial access via Citrix Bleed or compromised credentials, followed by extensive reconnaissance using native tools, credential harvesting, and careful data staging using MegaSync or Rclone. The group often spends 5-14 days in a network before deploying the encryptor.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1190 Exploit Public-Facing ApplicationExploitation of Citrix Bleed (CVE-2023-4966) for session hijacking
ImpactT1486 Data Encrypted for ImpactCustom encryptor with configurable encryption modes
ExfiltrationT1048 Exfiltration Over Alternative ProtocolMegaSync and Rclone for data theft to cloud storage
C2T1071 Application Layer ProtocolHTTPS-based C2 and legitimate remote access tools
Credential AccessT1003 OS Credential DumpingLSASS dumping and credential harvesting
Lateral MovementT1021 Remote ServicesPsExec and WMI for encryptor deployment

Notable Campaigns

INC Ransom has been linked to multiple significant campaigns:

Detection & Defense

Defend Against INC Ransom

Mjolnir Security provides specialized capabilities to detect and respond to INC Ransom operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • Threat Hunting Proactive hunting for INC Ransom TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of INC Ransom campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: March 1, 2026