Quick Summary
AllegedExecutive Summary
INC Ransom has listed DUCON, a manufacturing company based in Colombia, as a victim on its dark web portal. The listing date was July 28, 2026, and was identified by SOCRadar’s Dark Web Monitoring service. The inclusion of DUCON is notable as it represents a rare Latin American entity among the ransomware group’s recent targets, which have predominantly been U.S.-based organizations. DUCON’s industry, manufacturing, aligns with the typical targeting profile of INC Ransom. In the preceding 60 days, INC Ransom claimed 33 other victims, primarily within the business services, manufacturing, and general/uncategorized sectors, with a focus on the United States, Mexico, and the United Kingdom. DUCON’s industry places it within the group’s common targeting patterns, although its geographic location in Colombia deviates from the usual pattern. Other manufacturing companies recently claimed by INC Ransom include Minigrip, Jasper Plastics Solutions, Kewaunee Scientific, and Stuga Machinery, highlighting a consistent focus on this sector.
Technical Analysis
A search for stealer-log records associated with the domain ducon[.]com[.]co yielded no results within the specific query’s scope. It is important to note that this result represents data observed in the queried sample only and does not confirm that the organization is unaffected. The queried data set is paginated and partial, meaning that credentials potentially stored under alternate corporate domains or accessed via personal email aliases might not have been captured. Therefore, the absence of observed records should be interpreted as unconfirmed exposure rather than a definitive clean slate. Infostealer logs are a recognized primary method of initial access for INC Ransom. Access brokers commonly leverage these logs to acquire and validate corporate credentials. These credentials are then frequently used to gain access to systems via Microsoft 365, VPNs, or remote-access portals. Subsequently, ransomware deployment follows. While the current investigation found no direct evidence of exposed credentials, this possibility remains a viable threat vector. Given the nature of INC Ransom’s operations and the general threat landscape, continued monitoring for dark web listings and stealer-log activity related to DUCON is warranted. Proactive credential hygiene, including regular password rotation and multi-factor authentication reviews, is recommended. Additionally, monitoring for unusual activity on Microsoft 365, VPN gateways, and other remote access points should be considered as part of a comprehensive security posture.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.