INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory) — Threadlinqs Intelligence
As of 2026-05-30, INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory) is a critical-severity ransomware threat attributed to INC Ransom (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0199 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: RANSOMWARE
Attribution: INC Ransom · Russia · FINANCIAL
Joint advisory from Australia (ACSC), New Zealand (NCSC-NZ), and Tonga (CERT Tonga) warns of INC Ransom (GOLD IONIC / G1032) ransomware-as-a-service operations actively targeting critical
INC Ransom is a financially motivated ransomware-as-a-service (RaaS) operation active since July 2023, tracked as GOLD IONIC by Secureworks and G1032 by MITRE ATT&CK. The group operates a criminal franchise model where core developers build and maintain the ransomware platform and leak infrastructure, then lease access to affiliates who carry out attacks in exchange for a cut of ransom payments.
On March 6, 2026, Australia's ACSC, New Zealand's NCSC, and Tonga's CERT Tonga issued a joint advisory warning of INC Ransom affiliate operations actively targeting critical infrastructure across the Pacific region. This advisory marks the first tri-nation Pacific cybersecurity alert specifically addressing ransomware operations.
## Initial Access Vectors
INC Ransom affiliates employ multiple initial access methods:
1. **Exploitation of Public-Facing Applications**: Known exploitation of CVE-2023-3519 (Citrix NetScaler ADC/Gateway RCE, CVSS 9.8), CVE-2023-48788 (Fortinet EMS SQL injection), CVE-2024-57727 (SimpleHelp RMM path traversal), and CVE-2023-4966 (CitrixBleed session hijacking). A January 2025 campaign exploited FortiGate firewall management interfaces (FG-IR-24-535) exposed to the internet.
2. **Spear-Phishing**: Email-based social engineering campaigns with malicious attachments targeting organizational personnel.
3. **Purchased Credentials**: Valid account credentials acquired through Initial Access Brokers (IABs) on dark web forums, enabling direct access to VPN and RDP services.
## Attack Chain
Post-compromise, affiliates follow a consistent playbook:
- **Credential Harvesting**: Use of lsassy.py for LSASS credential dumping, esentutl for NTDS.dit extraction, HackTool.PS1.VeeamCreds for Veeam backup credential theft, and Kerberoasting against Active Directory service accounts.
- **Reconnaissance**: Domain enumeration via AdFind, net group commands, nltest for domain trust discovery, Advanced IP Scanner and NETSCAN.EXE for network mapping, and domain account/group discovery.
- **Lateral Movement**: Primarily via RDP with compromised domain admin credentials. PsExec renamed as winupd for remote service execution. WMIC used for multi-endpoint ransomware deployment.
- **Defense Evasion**: Disabling Windows Defender and security tools using HackTool.Win32.ProcTerminator.A. File deletion for anti-forensics. Masquerading PsExec as legitimate system files.
- **Data Exfiltration**: Archives created with 7-Zip (excluding media files to reduce size), exfiltrated via MegaSync or Rclone to cloud storage. In the Pennsylvania Office of Attorney General attack, over 5TB was exfiltrated.
- **Encryption**: INC Ransomware (S1139) deployed using AES-128 in CTR mode with Curve25519 Donna key exchange. Supports partial encryption with multi-threading for speed. Deletes volume shadow copies. Mounts hidden drives. Terminates blocking processes via Win32 Restart Manager. Ransom notes (INC-README.TXT and INC-README.HTML) printed to all connected printers and fax machines.
## Pacific Campaign (2025-2026)
Since January 2025, the ACSC has observed INC Ransom affiliates specifically targeting Australian healthcare sector entities using compromised accounts. The most significant Pacific attack occurred on June 15, 2025, when Tonga's Ministry of Health National Health Information System was fully encrypted, forcing medical staff to pen-and-paper record keeping. The group demanded $1 million USD, which the Tongan government refused to pay. Four sample documents were published on the leak site including communicable disease reports and patient records.
A joint Australian-New Zealand investigation attributed the Tonga attack to Roman Khubov (alias blackod), who controlled the malicious infrastructure used for data exfiltration. Microsoft Threat Intelligence tracks affiliate group Vanilla Tempest as adopting INC Ransomware as their primary payload since August 2024.
## Code Evolution
INC Ransomware source code was sold on underground foru
Weaknesses (CWE)
CWE-94, CWE-89, CWE-22, CWE-119
Target sectors: healthcare, education, government, critical-infrastructure, industrial, technology, financial
Target regions: Australia, New Zealand, Tonga, Pacific Island States, United States, United Kingdom, Europe
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2023-3519, CVE-2023-48788, CVE-2024-57727, CVE-2023-4966, T1190, T1566, T1078, T1588, T1059, T1047, T1569, T1078, T1078, T1562