INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory)

INC Ransom Affiliate Network Targeting Pacific Critical (TL-2026-0199), also tracked as INC Ransom Pacific Campaign 2025-2026, is a critical-severity ransomware operation scored CVSS 9.8, first published 2026-03-09. It is attributed to INC Ransom (Russia) with high confidence, affects Citrix NetScaler ADC, references 4 CVEs (CVE-2023-3519, CVE-2023-48788, CVE-2024-57727), maps to 33 MITRE ATT&CK techniques (T1003, T1021, T1036), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-0199

Threat ID
TL-2026-0199
Also known as
INC Ransom Pacific Campaign 2025-2026, Operation GOLD IONIC
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
RANSOMWARE
First published
2026-03-09
Last reviewed
2026-03-09
Attribution
INC Ransom
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
healthcare, education, government, critical-infrastructure, industrial, technology, financial
Target regions
Australia, New Zealand, Tonga, Pacific Island States, United States, United Kingdom, Europe
Detection rules
9
Indicators of compromise
24

Malware and tooling in INC Ransom Affiliate Network Targeting Pacific Critical

Malware and tooling: INC Ransomware - S1139, Lynx Ransomware, HackTool.PS1.VeeamCreds, Meterpreter

Joint advisory from Australia (ACSC), New Zealand (NCSC-NZ), and Tonga (CERT Tonga) warns of INC Ransom (GOLD IONIC / G1032) ransomware-as-a-service operations actively targeting critical infrastructure across the Pacific region. Affiliates use spear-phishing, exploitation of unpatched internet-facing devices (CVE-2023-3519 Citrix NetScaler, CVE-2023-48788 Fortinet EMS, CVE-2024-57727 SimpleHelp RMM), and purchased valid credentials from initial access brokers. Double-extortion with data leak site. Tonga Ministry of Health compromised June 2025 with $1M USD ransom demand. Roman Khubov (alias blackod) attributed by joint AU/NZ investigation.

How INC Ransom Affiliate Network Targeting Pacific Critical works

INC Ransom is a financially motivated ransomware-as-a-service (RaaS) operation active since July 2023, tracked as GOLD IONIC by Secureworks and G1032 by MITRE ATT&CK. The group operates a criminal franchise model where core developers build and maintain the ransomware platform and leak infrastructure, then lease access to affiliates who carry out attacks in exchange for a cut of ransom payments.

On March 6, 2026, Australia's ACSC, New Zealand's NCSC, and Tonga's CERT Tonga issued a joint advisory warning of INC Ransom affiliate operations actively targeting critical infrastructure across the Pacific region. This advisory marks the first tri-nation Pacific cybersecurity alert specifically addressing ransomware operations.

## Initial Access Vectors

INC Ransom affiliates employ multiple initial access methods:

1. **Exploitation of Public-Facing Applications**: Known exploitation of CVE-2023-3519 (Citrix NetScaler ADC/Gateway RCE, CVSS 9.8), CVE-2023-48788 (Fortinet EMS SQL injection), CVE-2024-57727 (SimpleHelp RMM path traversal), and CVE-2023-4966 (CitrixBleed session hijacking). A January 2025 campaign exploited FortiGate firewall management interfaces (FG-IR-24-535) exposed to the internet.

2. **Spear-Phishing**: Email-based social engineering campaigns with malicious attachments targeting organizational personnel.

3. **Purchased Credentials**: Valid account credentials acquired through Initial Access Brokers (IABs) on dark web forums, enabling direct access to VPN and RDP services.

## Attack Chain

Post-compromise, affiliates follow a consistent playbook:

- **Credential Harvesting**: Use of lsassy.py for LSASS credential dumping, esentutl for NTDS.dit extraction, HackTool.PS1.VeeamCreds for Veeam backup credential theft, and Kerberoasting against Active Directory service accounts.

- **Reconnaissance**: Domain enumeration via AdFind, net group commands, nltest for domain trust discovery, Advanced IP Scanner and NETSCAN.EXE for network mapping, and domain account/group discovery.

- **Lateral Movement**: Primarily via RDP with compromised domain admin credentials. PsExec renamed as winupd for remote service execution. WMIC used for multi-endpoint ransomware deployment.

- **Defense Evasion**: Disabling Windows Defender and security tools using HackTool.Win32.ProcTerminator.A. File deletion for anti-forensics. Masquerading PsExec as legitimate system files.

- **Data Exfiltration**: Archives created with 7-Zip (excluding media files to reduce size), exfiltrated via MegaSync or Rclone to cloud storage. In the Pennsylvania Office of Attorney General attack, over 5TB was exfiltrated.

- **Encryption**: INC Ransomware (S1139) deployed using AES-128 in CTR mode with Curve25519 Donna key exchange. Supports partial encryption with multi-threading for speed. Deletes volume shadow copies. Mounts hidden drives. Terminates blocking processes via Win32 Restart Manager. Ransom notes (INC-README.TXT and INC-README.HTML) printed to all connected printers and fax machines.

## Pacific Campaign (2025-2026)

Since January 2025, the ACSC has observed INC Ransom affiliates specifically targeting Australian healthcare sector entities using compromised accounts. The most significant Pacific attack occurred on June 15, 2025, when Tonga's Ministry of Health National Health Information System was fully encrypted, forcing medical staff to pen-and-paper record keeping. The group demanded $1 million USD, which the Tongan government refused to pay. Four sample documents were published on the leak site including communicable disease reports and patient records.

A joint Australian-New Zealand investigation attributed the Tonga attack to Roman Khubov (alias blackod), who controlled the malicious infrastructure used for data exfiltration. Microsoft Threat Intelligence tracks affiliate group Vanilla Tempest as adopting INC Ransomware as their primary payload since August 2024.

## Code Evolution

INC Ransomware source code was sold on underground forums in March 2024 for approximately $300,000. This led to the emergence of Lynx ransomware, which shares over 70% code similarity (48% matched functions) with INC, demonstrating payload rebranding. As of mid-2025, over 200 victims appeared on INC's data leak site, with the group ranking as the most deployed ransomware by victim postings in July 2025.

---

**Revalidated on 2026-03-12**

POST-PUBLICATION DEVELOPMENTS (as of 2026-03-12): (1) LEGAL SECTOR EXPANSION: Since the Pacific advisory, INC Ransom has rapidly pivoted to target the legal sector, claiming 20 law firms in 2026 with a concentrated burst of 10 firms posted to their leak site within 48 hours (Halcyon, March 2026). The clustering suggests a possible supply chain compromise of a shared legal technology provider or managed services vendor. (2) NZ HEALTH VICTIM CONFIRMED: Dark Reading confirmed a previously unreported New Zealand health-sector organization was attacked in May 2025 — servers and endpoints encrypted, significant data exfiltrated, and the dataset later published on INC's leak site. This predates the Tonga MoH attack by approximately one month and strengthens the pattern of systematic Pacific healthcare targeting. (3) ACSC INCIDENT COUNT: The ACSC disclosed responding to 11 INC ransomware incidents in Australia between July 2024 and December 2025, predominantly healthcare and professional services. (4) KHUBOV STATUS: No formal U.S. or international sanctions, indictments, or extradition actions against Roman Khubov (blackod) have been publicly announced as of this date, despite the joint AU/NZ attribution. (5) LYNX DERIVATIVE ACTIVITY: The INC-derived Lynx ransomware continues to operate independently with 91% Linux code similarity and 70.8% Windows matched functions, representing an ongoing parallel threat vector from the March 2024 source code sale. (6) RANKING: INC Ransom is listed among the top 10 most infamous ransomware groups to watch in 2026 (NordStellar), confirming sustained operational tempo.

MITRE ATT&CK techniques used in TL-2026-0199

credential-access

T1003 OS Credential Dumping; T1558 Steal or Forge Kerberos Tickets

lateral-movement

T1021 Remote Services; T1570 Lateral Tool Transfer

defense-evasion

T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information

discovery

T1046 Network Service Discovery; T1049 System Network Connections Discovery; T1069 Permission Groups Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1120 Peripheral Device Discovery; T1135 Network Share Discovery

execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1569 System Services

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

collection

T1074 Data Staged; T1560 Archive Collected Data

initial-access

T1190 Exploit Public-Facing Application; T1566 Phishing

impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement; T1657 Financial Theft

exfiltration

T1537 Transfer Data to Cloud Account

resource-development

T1588 Obtain Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in INC Ransom Affiliate Network Targeting Pacific Critical

  • Citrix — NetScaler ADC
    Vulnerable versions: 13.1 before 13.1-49.13; 13.0 before 13.0-91.13; 12.1 (EOL)
    Fixed in: 13.1-49.13+; 13.0-91.13+
  • Citrix — NetScaler Gateway
    Vulnerable versions: 13.1 before 13.1-49.13; 13.0 before 13.0-91.13; 12.1 (EOL)
    Fixed in: 13.1-49.13+; 13.0-91.13+
  • Fortinet — FortiClient EMS
    Vulnerable versions: Versions affected by CVE-2023-48788
    Fixed in: Patched versions per vendor advisory
  • Fortinet — FortiOS
    Vulnerable versions: 7.0 before 7.0.15
    Fixed in: 7.0.15+
  • SimpleHelp — SimpleHelp RMM
    Vulnerable versions: Versions affected by CVE-2024-57727
    Fixed in: Patched versions per vendor advisory
  • Microsoft — Windows Server
    Vulnerable versions: 2016; 2019; 2022
    Fixed in: N/A - target of lateral movement and encryption

Remediation for INC Ransom Affiliate Network Targeting Pacific Critical

Patches

  • Citrix NetScaler ADC/Gateway: Upgrade to 13.1-49.13+ or 13.0-91.13+ (CVE-2023-3519)
  • Fortinet EMS: Apply vendor patch for CVE-2023-48788
  • SimpleHelp RMM: Apply vendor patch for CVE-2024-57727
  • Citrix NetScaler: Upgrade to patched versions for CVE-2023-4966 (CitrixBleed)
  • FortiOS: Upgrade to 7.0.15+ to address FG-IR-24-535

Immediate actions

  • Patch CVE-2023-3519 on all Citrix NetScaler ADC/Gateway appliances immediately
  • Patch CVE-2023-48788 on all Fortinet EMS installations
  • Patch CVE-2024-57727 on all SimpleHelp RMM instances
  • Patch CVE-2023-4966 (CitrixBleed) on all affected Citrix appliances
  • Audit and restrict internet-facing FortiGate management interfaces
  • Reset all domain admin and service account passwords
  • Block known C2 IP 185.174.100.204 at perimeter
  • Block MegaSync and Rclone cloud sync traffic at firewall
  • Disable or restrict RDP access to only required systems with MFA

Workarounds

  • Restrict NetScaler Gateway/AAA virtual server access to trusted IP ranges only
  • Disable FortiGate management interface internet exposure
  • Block outbound connections to MegaSync and Rclone domains
  • Monitor for PsExec renamed as winupd or other masqueraded filenames
  • Alert on 7-Zip command-line execution with archive parameters

Longer-term hardening

  • Deploy EDR with behavioral detection for ransomware encryption patterns
  • Implement network segmentation to isolate critical healthcare systems
  • Enable MFA on all VPN, RDP, and privileged accounts
  • Monitor for credential dumping tools (lsassy, esentutl, Mimikatz)
  • Implement LAPS for local admin password management
  • Deploy application whitelisting to prevent unauthorized tool execution
  • Establish offline backup strategy with regular recovery testing
  • Implement DNS filtering to block Tor and known ransomware leak site domains

CVEs associated with INC Ransom Affiliate Network Targeting Pacific Critical

CVE-2023-3519, CVE-2023-48788, CVE-2024-57727, CVE-2023-4966

Weaknesses (CWE) in INC Ransom Affiliate Network Targeting Pacific Critical

CWE-94, CWE-89, CWE-22, CWE-119

Timeline of INC Ransom Affiliate Network Targeting Pacific Critical

  • INC Ransom group emerges as a ransomware-as-a-service operation, beginning to list victims on their dark web leak site
  • Citrix discloses CVE-2023-3519 (CVSS 9.8) affecting NetScaler ADC and Gateway, later exploited by INC Ransom affiliates for initial access
  • INC Ransom affiliates observed exploiting CVE-2023-3519 Citrix NetScaler vulnerability for initial access to victim networks, including Yamaha Motor Philippines attack (37GB exfiltrated)
  • INC Ransomware source code sold on underground forums for approximately $300,000, leading to derivative operations including Lynx ransomware
  • Microsoft Threat Intelligence tracks Vanilla Tempest affiliate group adopting INC Ransomware as primary payload after previously using BlackCat, Quantum Locker, Zeppelin, and Rhysida
  • ACSC begins observing INC Ransom affiliates targeting Australian healthcare sector entities using compromised accounts and privilege escalation
  • INC Ransom affiliates exploit FortiGate firewall management interface vulnerability (FG-IR-24-535) in FortiOS 7.0.15 for initial access, achieving full domain compromise within 48 hours
  • New Zealand health-sector organization suffers INC Ransom attack — servers and endpoints encrypted, significant data exfiltrated. INC Ransom later claims the attack and publishes stolen dataset on leak site (reported by NCSC-NZ via Dark Reading). [Source: https://www.darkreading.com/threat-intelligence/inc-ransomware-healthcare-oceania]
  • Tonga Ministry of Health National Health Information System fully encrypted by INC Ransom affiliate Roman Khubov (blackod), forcing medical staff to pen-and-paper record keeping
  • Tonga government refuses to pay $1 million USD ransom demand; INC Ransom publishes sample documents including communicable disease reports and patient records on leak site
  • INC Ransom ranks as most deployed ransomware by victim postings with over 200 victims on data leak site, healthcare organizations accounting for 29% of attacks
  • Joint Australian-New Zealand cyber investigation identifies Roman Khubov (alias blackod) as the affiliate behind the Tonga Ministry of Health ransomware attack
  • Australia ACSC, New Zealand NCSC, and Tonga CERT Tonga publish joint advisory warning of INC Ransom affiliate model targeting Pacific critical infrastructure
  • The Cyber Express publishes analysis characterizing INC Ransom''s affiliate model as a ''franchise model putting critical infrastructure on the chopping block,'' detailing how the RaaS structure lowers the barrier for affiliates to target critical networks. [Source: https://thecyberexpress.com/inc-ransom-franchise-model/]
  • Cyble publishes detailed analysis of the tri-nation advisory and INC Ransom Pacific campaign, documenting affiliate TTPs and exploitation patterns
  • Halcyon reports INC Ransom has pivoted to aggressive legal sector targeting — 20 law firms claimed in 2026, with 10 firms posted to the leak site in a 48-hour burst. Possible supply chain compromise of a shared legal technology vendor suspected. [Source: https://www.halcyon.ai/ransomware-alerts/inc-ransom-group-mounts-rapid-campaign-against-law-firms]
  • As of 2026-05-29, INC Ransom (GOLD IONIC/G1032) remains fully operational: ransomware.live shows 814 leak-site victims, "inactive 0 days," and a new posting dated 2026-05-30, with a 2026 pivot to law firms (20 claimed, per Halcyon). No takedown, no sanctions/indictment of Khubov, and no successor; the four initial-access CVEs are patched/in KEV but still actively exploited.

Sources cited for INC Ransom Affiliate Network Targeting Pacific Critical

Threats related to INC Ransom Affiliate Network Targeting Pacific Critical

Detection coverage for TL-2026-0199

As of 2026-03-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0199 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats