We knew about V-Silicon attack before it was claimed: This is how hackers exposed themselves
Attackers were preparing to target the industrial controls of semiconductor factories.

- Cybernews researchers found an exposed hacker server linked to an INC Ransomware attack on semiconductor company V-Silicon.
- The ransomware supported unusual systems, suggesting attackers may have prepared to target industrial controls or chip production equipment.
- Evidence suggests attackers may have accessed V-Silicon weeks earlier and possibly exposed third-party infrastructure linked to NXP and UnitedDS.
- Researchers said reliable, isolated backups are critical because affected companies may otherwise need to rebuild infrastructure from scratch.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Cybernews researchers uncovered an active ransomware campaign against multinational semiconductor company V-Silicon after discovering an exposed hacker server.
Cybercriminals are not immune to human errors. A simple security mistake made by an attacker can sometimes expose ongoing ransomware operations and how they function.
Recently, Cybernews researchers discovered an exposed web directory that functioned as a staging server for a ransomware attack.
A subsequent investigation linked the discovered infrastructure to an attack against V-Silicon, a multinational semiconductor company that develops chips used in smart TVs and display devices.
The campaign was attributed to INC Ransomware, a ransomware-as-a-service (RaaS) operation that has been active since 2023.
Our researchers say the exposed server contained hacking tools built specifically for the campaign. The evidence found on the server allowed the team to reconstruct the attack chain before it hit the public.
We alerted V-Silicon to the exposed data on July 17th. One day later, the INC ransomware group published V-Silicon on its leak site, claiming responsibility for the attack.
V-Silicon was established in 2018 after acquiring the TV semiconductor business of Sigma Designs. The company has headquarters in Hefei, China, with teams in Shanghai, Taipei, Silicon Valley, Eindhoven, and Hanoi.
Attackers were getting ready to target industrial controls
The ransomware was built to run on a wide range of computer systems, including less common platforms used in environments, including PowerPC, RISC-V, SPARC, and IBM's s390x.
That is quite unusual because many ransomware operations focus primarily on standard Windows and Linux servers.
According to Cybernews researchers, support for these systems suggests that the attackers may have intended to encrypt embedded controllers, industrial systems, or older semiconductor manufacturing equipment.
If accurate, that would indicate the attackers may have been prepared to move beyond office networks and potentially disrupt operational technology used in chip production.
The attack may have started weeks earlier
The exposed server suggests that the attackers may have maintained access to V-Silicon's environment for far longer than initially apparent.
While most reconnaissance and attack preparation took place around July 14th, our researchers also found exports of the company's Active Directory environment dated June 16th. Those files list users and computers inside the corporate network.
Our team says it remains unclear whether the attackers had maintained access for nearly a month or whether the exported files had simply been copied to the server later.
Third-party may also have been compromised
The investigation also suggests the breach may have extended beyond V-Silicon itself.
Data recovered from the attacker server referenced third-party infrastructure, including a Server Message Block (SMB) share associated with semiconductor company NXP at its Eindhoven location and FTP credentials linked to UnitedDS.
This shows that investigations based solely on ransomware leak sites may underestimate the scope of ransomware attacks.“Such a data leak allows researchers and network defenders to identify the breach scope outside of what is published on a gang’s leak site,” our researchers explained.
“The artifacts found on the exposed server indicate that during network enumeration, third-party infrastructure and data could have also been compromised.”
AI-generated scripts
According to the team, the attackers carried out much of the operation manually instead of relying on automated malware.
They searched the victim's network for valuable files, gathered information about systems and users, and wrote custom scripts for different stages of the attack.
Most of those scripts were written in Python, but Bash and PowerShell scripts were also used. Many comments included references to V-Silicon's internal infrastructure, employee names, and hardcoded credentials.
Researchers also noticed coding patterns that suggest some scripts may have been generated with artificial intelligence or created from reusable templates before being customized for the victim.
The technical details of the attack chain are listed here.
What is known about INC Ransomware?
INC Ransomware, the suspect behind the attack, has grown into one of the world's most active ransomware operations since emerging in 2023. The group operates under a RaaS model, providing malware to affiliated attackers in exchange for a share of ransom payments.
In 2024, the gang took a blow when an affiliate or core operator of INC Ransom advertised the ransomware's complete Windows and Linux/ESXi source code on dark web forums for around $300,000. The leak led to the creation of other ransomware variants, such as Lynx and Sinobi.
Despite its source code being leaked, the group has continued updating its tools and remains among the most prolific ransomware operations currently active. Based on the claimed victims, it ranks 6th, behind only the Qilin, Lockbit, Akira, Play, and Cl0p gangs.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Attackers keep exposing their infrastructure
This is not the first time Cybernews researchers have uncovered active cyberattacks by discovering publicly exposed web directories used by attackers.
An exposed server revealed that Jerry’s Store, a marketplace for stolen credit cards, has been using Amazon, Temu, Lyft, and other legitimate merchants to do its validity checks.
Research also previously revealed a massive operation that siphoned data from 5 million users on the Spanish check-in service platform Chekin and the Austrian hotel management software provider Gastrodat.
An unprotected server also exposed that a Russian hacker used Anthropic's Claude to breach hotel booking platforms and expose 2.1 million email addresses.
How to mitigate the risks?
While mitigation of a successfully executed ransomware attack is a tricky process, Cybernews researchers highlight that having up-to-date backups always helps.
“The best outcome is if the company has any surviving backups that were not deleted or encrypted. In that case, the company can identify when the attack started, what the initial access vectors were, restore before the attack started, and immediately patch the initial access vectors,” they said.
However, our researchers remind us that this is usually not possible because companies often do not back up their systems or do not make airgapped copies of their backups.
“In cases where suitable backups are not available, most of the infrastructure would need to be set up from scratch,” they added.
Investigation timeline
Obtained snapshot of attacker’s server: July 16th,
Started investigation: July 17th, 2026
Initial disclosure: July 17th, 2026
INC Ransomware posts V-Silicon to their victim site: July 18th, 2026