Latest / Tech Talks With Kinsoft / Five Eyes Warning – INC Ransom Targets Australian Healthcare
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Imagine you
- 0:03are the IT director for like a regional hospital
- 0:06network. It is 3 .0 a .m. on a Tuesday and your
- 0:10phone rings. Yeah, that is never a good time
- 0:13for the phone to ring. No, definitely not. And,
- 0:15you know, it is not just a server outage. Every
- 0:17emergency room monitor is locked. Patient history
- 0:19databases are just completely inaccessible. And
- 0:22there is a digital ransom note sitting right
- 0:23on your desk. Which is an absolute nightmare
- 0:26scenario. Right. But the attackers aren't just
- 0:28demanding money to unlock the screens. They are
- 0:31threatening to publish 10 ,000 highly sensitive
- 0:33psychiatric records on the public internet by
- 0:35sunrise if you don't pay. Exactly. And that terrifying
- 0:40scenario isn't a hypothetical at all. It is the
- 0:43exact operating model of a threat that is actively
- 0:46dismantling critical infrastructure right now.
- 0:48Yeah. And that operational reality is the entire
- 0:51focus of our session today. We are breaking down
- 0:54a critical joint cybersecurity advisory issued
- 0:56on March 12, 2026. And this warning comes straight
- 0:59from the top, right? Oh, absolutely. We are talking
- 1:02about the Australian Cyber Security Center, the
- 1:04ACSC, working in tandem with New Zealand's NCSC
- 1:09and CERT Tonga. They are sounding a massive alarm
- 1:12about a group known as INC Ransom. Right. And
- 1:15their relentless campaign against Australian
- 1:18health care and critical infrastructure across
- 1:20the Pacific. OK, let's unpack this, because to
- 1:23actually defend against this group, we have to
- 1:25understand their specific business model. I mean,
- 1:27who exactly is INC Ransom? And what is the true
- 1:30scale of the damage outlined in this advisory?
- 1:33Well, in the threat intelligence community, you
- 1:35will sometimes see INC ransom tracked under names
- 1:37like Tarnished Scorpion or Goldie Ionic. Okay.
- 1:42Yeah, and the advisory confirms that between
- 1:44July 2024 and December 2025, this specific group
- 1:48breached at least 11 different Australian organizations.
- 1:51Oh, 11. Yeah, 11 confirmed. But looking at that
- 1:54number in isolation is actually kind of deceptive.
- 1:56Since early 2025, they have aggressively expanded
- 1:58their footprint into the broader Pacific. Right,
- 2:01because the advisory mentioned New Zealand and
- 2:02Tonga. Exactly. They successfully disrupted vital
- 2:05health networks there. And they are not just...
- 2:09you know, spraying and praying, they are systematically
- 2:12targeting health care and professional services.
- 2:14I mean, 11 confirmed major breaches of critical
- 2:17infrastructure in an 18 month window is a staggering
- 2:20success rate for one group. It really is. It
- 2:23kind of begs the question of how they are scaling
- 2:26so rapidly. The advisory points out that INC
- 2:29Ransom utilizes a ransomware as a service model
- 2:32or RAHAS. I've heard it described as a franchise
- 2:35model for cybercrime. Yeah, that's a great way
- 2:37to put it. Yeah. Where developers basically rent
- 2:39out their malware toolkits to less sophisticated
- 2:42criminals, which massively lowers the barrier
- 2:44to entry. If they are essentially franchising
- 2:48this out, does this mean we are facing a much
- 2:50higher volume of attacks rather than highly sophisticated
- 2:53targeted ones? What's fascinating here is how
- 2:56this RIS model turns cybercrime into a highly
- 3:00scalable, almost industrialized business supply
- 3:03chain. I mean, in the old days, a hacker had
- 3:05to be a master of everything. Right. They had
- 3:07to build it all from scratch. Exactly. They had
- 3:09to write the exploit, breach the network, build
- 3:11the encryption algorithm, and figure out how
- 3:13to collect the money. INC Ransom just splits
- 3:16that workload. So they specialize. Yeah. The
- 3:19core developers act like a Silicon Valley SaaS
- 3:21startup. They build the backend infrastructure,
- 3:24the encryption tools, the dark web leak sites,
- 3:27and the payment portals. That is wild. They even
- 3:30provide IT help desks support for their victims.
- 3:33Like they offer live chat to walk a hospital
- 3:36administrator through the process of acquiring
- 3:38Bitcoin. Are you serious? Live chat support.
- 3:41So they really operate with the efficiency of
- 3:44a legitimate corporation. Completely. And instead
- 3:47of launching the attacks themselves, they lease
- 3:49that entire back end to affiliates. And these
- 3:52affiliates are basically independent contractors.
- 3:54OK, so the affiliates do the actual breaking
- 3:56in. Yes. They don't need to know how to code
- 3:59complex malware. They just need to know how to
- 4:01break into a network. Once they in, they deploy
- 4:05the least INC ransom toolkit. And then they just
- 4:07split the profits. Exactly. The core group takes
- 4:11a percentage of the final ransom and the affiliate
- 4:13keeps the rest. This drastically lowers the barrier
- 4:17to entry, flooding the threat landscape with
- 4:19financially motivated opportunistic attackers.
- 4:22Wow. That volume fundamentally changes the math
- 4:25for defenders. I mean, we are no longer trying
- 4:28to stop one elite master thief. No. We have to
- 4:31defend against 100 opportunistic smash and grabbers.
- 4:35Which, you know, brings us to the tactical mechanics
- 4:37of the breach. How are these affiliates actually
- 4:40getting past the perimeter of highly sensitive
- 4:43health care networks? Right. So what does their
- 4:45entry strategy look like today? Yeah, exactly.
- 4:47Well, the advisory highlights that they rarely
- 4:50burn zero day. custom -built exploits to gain
- 4:53initial access. They rely on the path of least
- 4:56resistance. Which usually means human error,
- 4:58right? Usually, yeah. First, they deploy highly
- 5:00targeted spear phishing campaigns. And we aren't
- 5:03talking about generic spam emails riddled with
- 5:05typos. These are sophisticated social engineering
- 5:08lures, often tailored specifically to healthcare
- 5:11administrators or IT staff, designed to just
- 5:13harvest their login credentials. Okay, so phishing
- 5:17is step one. What else? Second. They constantly
- 5:19scan the public -facing internet for unpatched
- 5:22systems. They exploit known vulnerabilities in
- 5:25VPNs or remote desktop gateways before the IT
- 5:28team even has a chance to apply the latest security
- 5:31update. Wow. But the advisory also mentions something
- 5:34that feels much harder to defend against, which
- 5:38is initial access brokers. Oh, yeah. That is
- 5:41perhaps the most concerning vector. Really? Definitely.
- 5:43The cybercrime economy is so specialized now
- 5:46that there's an entire sub -industry of initial
- 5:48access brokers, or IABs. And what do they do
- 5:51exactly? These are threat actors whose only job
- 5:53is to compromise network credentials. They usually
- 5:56do this through massive automated credential
- 5:58stuffing attacks or by purchasing logs from info
- 6:01-stealing malware. Okay, so they just steal the
- 6:03passwords. Right, but they don't deploy ransomware.
- 6:05They simply take that working username and password,
- 6:08package it, and sell it on dark web forums to
- 6:10a ROS affiliate. oh wow so the affiliate just
- 6:13buys the password logs into the hospital's vpn
- 6:16and bypasses the external perimeter entirely
- 6:19exactly why bother breaking a window when you
- 6:23can literally just buy the key to the front door
- 6:25online that is absolutely terrifying okay so
- 6:28the affiliate has purchased the credentials they
- 6:31have logged into the network and maybe they are
- 6:34sitting on like a receptionist's computer What
- 6:38happens next? Well, sitting on a receptionist's
- 6:40computer doesn't get them the millions of dollars
- 6:42they want. Yeah, obviously not. That local machine
- 6:45doesn't have access to the core patient databases,
- 6:47and it certainly doesn't have the permissions
- 6:49required to deploy ransomware across the entire
- 6:52organization. So they have to move. The advisory
- 6:54emphasizes lateral movement and privilege escalation.
- 6:57Exactly. They need to move laterally from that
- 7:00initial entry point, jumping from workstation
- 7:03to server, just hunting for the network's central
- 7:05nervous system, which... in most enterprise environments,
- 7:09is the domain controller. Right, the domain controller.
- 7:12I hear that term thrown around constantly in
- 7:14these advisories. Let's break down mechanically
- 7:17why it is the ultimate prize for these affiliates.
- 7:20So the domain controller runs Active Directory.
- 7:23It is the system that basically dictates who
- 7:26gets access to what. It holds the cryptographic
- 7:29hashes for every password and manages the permissions
- 7:32for every user and device on the network. Okay,
- 7:35so it's the master key. Essentially, yes. If
- 7:38an attacker can escalate their privileges and
- 7:40compromise the domain controller, they rewrite
- 7:42the rules of the network. They can grant themselves
- 7:44permanent, invisible administrative access. Wow.
- 7:48And more importantly, instead of having to manually
- 7:50hack 5 ,000 individual hospital computers one
- 7:53by one, they can use the domain controller to
- 7:56push their ransomware out to every single machine
- 7:58simultaneously. Almost as if it were a legitimate
- 8:01company -wide software update. But to pull that
- 8:04off, they need a significant amount of time inside
- 8:06the network without getting caught. And here's
- 8:08where it gets really interesting. The ACSC advisory
- 8:11explicitly warns that INC ransom affiliates use
- 8:15legitimate, everyday IT tools to avoid detection.
- 8:18Yeah, that's a huge problem for defenders. I
- 8:20mean, we are talking about software like 7 -Zip,
- 8:23which is a standard file archiving tool, and
- 8:26SirClone, which is used to sync data to cloud
- 8:29storage. But I am stuck on this concept. How
- 8:31so? Well, it's like a burglar wearing a utility
- 8:34company uniform to walk right past the security
- 8:37cameras. If they are using the exact same tools
- 8:39that our IT departments use every day, how can
- 8:42a defender possibly spot them without shutting
- 8:44down normal, legitimate operations? That is the
- 8:48exact dilemma defenders face, and it's a a tactic
- 8:50known as living off the land. Living off the
- 8:52land, okay. Yeah. If an attacker brings custom
- 8:54known malware into your environment, an endpoint
- 8:56detection system will flag the malicious signature
- 8:59immediately. It is noisy. Right, the alarms go
- 9:02off. But a tool like 7 -Zip has no malicious
- 9:05signature. It is a trusted, digitally signed
- 9:08application. The security software sees a legitimate
- 9:11tool doing exactly what it was programmed to
- 9:14do, which is compress files. Okay, so the software
- 9:16just ignores it. Exactly. To spot the attacker,
- 9:19defenders have to shift their focus from looking
- 9:21at the tool to analyzing the behavior. So it
- 9:24is not about what the tool is. It is about context.
- 9:26It's analyzing who is using it, when they are
- 9:29using it, and what they are applying it to. Precisely.
- 9:32Behavioral heuristics look for anomalies. An
- 9:35IT admin using 7 -zip during standard business
- 9:38hours to compress a small folder of text files
- 9:41is normal behavior. Right. But if 7 -zip is suddenly
- 9:44executed at 2 .0 AM, by a service account that
- 9:47normally doesn't interact with the desktop, and
- 9:50it is using command line arguments to compress
- 9:52500 gigabytes of data from a highly sensitive
- 9:55SQL Server database. Yeah, that is a red flag.
- 9:58Exactly. That combination of the behaviors should
- 10:00trigger an immediate high -priority alert in
- 10:02a modern security operations center. That makes
- 10:04perfect sense. So the affiliate is living off
- 10:07the land. using seven zip to quietly bundle up
- 10:10these massive databases and then using a tool
- 10:13like sir clone to siphon that data out of the
- 10:15network it's disguised as regular outbound cloud
- 10:18traffic right And they are going through this
- 10:21incredibly complex, stealthy process before they
- 10:24ever drop the actual ransomware. I mean, this
- 10:26completely changes the narrative of what ransomware
- 10:29even is. It really does. We have firmly left
- 10:32the era where the primary goal was simply locking
- 10:35computers. We are operating in the reality of
- 10:38double extortion. And the advisory makes this
- 10:40crystal clear. INC ransom isn't just freezing
- 10:43systems to halt operations. They're exfiltrating
- 10:46the data first. Yes, the data theft is key. And
- 10:48in the context of the Australian health networks
- 10:50they have breached, we are talking about highly
- 10:52personal, confidential medical histories, diagnostic
- 10:55imaging, and psychiatric evaluations. Which provides
- 10:58them with an insurmountable level of leverage.
- 11:00Definitely. They steal the data, they deploy
- 11:03the locker to paralyze the hospital, and then
- 11:05they deliver the ultimatum. Like, pay the first
- 11:07ransom to get the decryption key so you can turn
- 11:10your monitors back on, and pay the second ransom
- 11:12to stop us from dumping your patient's most intimate
- 11:15medical secrets onto the dark web. This is why
- 11:18health care is not an accidental target for this
- 11:20RAS ecosystem. It is a deeply cynical, highly
- 11:24calculated strategy based on operational pressure.
- 11:28Because they can't afford to be offline. Exactly.
- 11:30If a manufacturing plant is locked out of its
- 11:33systems, it is a massive financial headache.
- 11:35They lose revenue every hour the assembly line
- 11:38is down. Right. But if a hospital is locked out
- 11:40of its systems, the stakes immediately become
- 11:42physical. Operational downtime means diverted
- 11:45ambulances, delayed surgeries, and doctors unable
- 11:48to access critical allergy information before
- 11:50administering medication. So what does this all
- 11:53mean? It feels like they are weaponizing the
- 11:55very mission of health care providers against
- 11:57them. How does an organization even begin to
- 12:01calculate the risk when human safety is on the
- 12:03line? If we connect this to the bigger picture,
- 12:06this advisory forces us to re -evaluate our definition
- 12:10of critical infrastructure vulnerabilities. So?
- 12:12Well, for decades, a cyber breach was viewed
- 12:16through the lens of data privacy or financial
- 12:18loss. It was an IT problem handled by the IT
- 12:21department. Right, just a tech issue. Yeah, but
- 12:24when an affiliate buys a stolen password for
- 12:26$50 and uses it to bring regional patient care
- 12:29to a grinding halt, it ceases to be an IT issue.
- 12:33It becomes a systemic public safety crisis. Absolutely.
- 12:37It proves that the physical resilience of our
- 12:38society is now entirely dependent on the digital
- 12:41resilience of these networks. So focusing on
- 12:43the organizations listening to this right now,
- 12:45we understand the severity. We know INC Ransom
- 12:48scales through a franchise model. We know they
- 12:50buy credentials, move laterally to the domain
- 12:53controller, live off the land with 7 -zip distilled
- 12:55data, and then execute double extortion. The
- 12:58critical question now is defense. Right. How
- 13:01do we stop them? Exactly. Based on this joint
- 13:04advisory, how do Australian critical infrastructure
- 13:06providers actually build a shield against a threat
- 13:09that is this multifaceted? Well, the beauty of
- 13:12this advisory is that it functions as a highly
- 13:14actionable defense playbook. It outlines specific
- 13:18countermeasures designed to break the attacker's
- 13:21kill chain at every single stage we just discussed.
- 13:23OK, so where do we start? It starts at the very
- 13:25beginning, which is initial access. Since we
- 13:29know affiliates rely heavily on purchased credentials
- 13:31from initial access brokers, organizations have
- 13:34to render those stolen passwords useless. But
- 13:37the standard advice is always, you know, use
- 13:39stronger passwords or enforce credential hygiene.
- 13:42But if an attacker is literally buying my password
- 13:45on the dark web. It doesn't really matter if
- 13:48it has 20 characters and a dozen special symbols,
- 13:50right? If they have it, they have it. It sounds
- 13:52like we have to assume they already have the
- 13:54keys to the front door, which means we need significantly
- 13:57smarter locks on the inside. Which is exactly
- 14:00why the advisory heavily emphasizes the deployment
- 14:02of phishing -resistant multi -factor authentication,
- 14:05or MFA, on all external facing services. Phishing
- 14:09-resistant MFA. Yes, and the distinction of phishing
- 14:11-resistant is critical here. I want to pause
- 14:13on that because it's a vital point. A lot of
- 14:15organizations think they are secure because they
- 14:18use SMS text messages or app -based push notifications
- 14:22for MFA. Why aren't those standard methods enough
- 14:26to stop an INC ransom affiliate? Because the
- 14:29attackers have adapted. Affiliates now use adversary
- 14:33-in -the -middle proxy attacks. What does that
- 14:35look like? Let's say you click a sophisticated
- 14:37phishing link. It takes you to a fake login page
- 14:40that looks exactly like your corporate Microsoft
- 14:42365 portal. You type your password. Okay. The
- 14:46fake site then prompts you for your SMS code.
- 14:48You look at your phone, type in the six digits,
- 14:50and hit enter. In milliseconds, the proxy server
- 14:53captures that code and forwards it to the real
- 14:55Microsoft site, logging the attacker in. Oh,
- 14:58wow. Yeah. They bypass your SMS MFA in real time.
- 15:02So what makes something genuinely phishing -resistant
- 15:04then? Physical cryptography. Yeah. Phishing -resistant
- 15:07MFA, like FIDO2 hardware security keys, which
- 15:10is a physical USB device you plug into your laptop,
- 15:13relies on cryptographic proof. Okay, so it's
- 15:15a physical thing. Exactly. The hardware key authenticates
- 15:19the physical domain you are visiting. If you
- 15:21are on a fake proxy site, the hardware key recognizes
- 15:25the domain mismatch and simply refuses to hand
- 15:28over the cryptographic token. That is brilliant.
- 15:31Yeah. The authentication fails. Even if the affiliate
- 15:34buys your password, without that physical piece
- 15:36of hardware, they cannot get through the VPN.
- 15:39That makes a massive difference. But let's assume
- 15:41the worst case scenario here. Let's assume an
- 15:43affiliate somehow finds a gap, maybe an unpatched
- 15:46legacy server, and gets a foothold inside the
- 15:49network. We know their next step is hunting for
- 15:51the domain controller. How do we stop that lateral
- 15:55movement? Defenders must implement the principle
- 15:58of least privilege and aggressively limit privilege
- 16:01escalation paths. Meaning what, practically?
- 16:03You have to design the network with the assumption
- 16:05that a breach will occur. If a standard user
- 16:08account is compromised, that account should be
- 16:10locked down in a segmented environment. It should
- 16:13not have the ability to run administrative scripts,
- 16:16access sensitive file shares, or communicate
- 16:18with the domain controller over unnecessary ports.
- 16:22You isolate the infection by moving the pathways
- 16:24the attacker needs to travel. You are essentially
- 16:27building bulkheads in a submarine. Like if one
- 16:30compartment floods, the ship doesn't sink. That's
- 16:32a perfect analogy, yeah. And what about the stealth
- 16:34phase where they are using 7 -Zip and SirClone?
- 16:38We talked about behavioral heuristics earlier.
- 16:40Right. Organizations must deploy advanced endpoint
- 16:42detection and response, or EDR, solutions that
- 16:45monitor behavior, not just file signatures. So
- 16:48the software has to be smart enough to catch
- 16:50the contact. Exactly. And you need a security
- 16:53operations team or a managed service provider
- 16:56actively hunting for those anomalies we discussed.
- 16:58If AirClone suddenly starts initiating massive
- 17:01outbound data transfers to a cloud storage provider
- 17:04your company doesn't use, the network should
- 17:06automatically sever that connection. Finally,
- 17:09the advisory tackles the grim reality of incident
- 17:12response readiness. If the behavioral monitoring
- 17:14fails and the data is successfully exfiltrated,
- 17:18what is the protocol? This raises an important
- 17:21question. Is your organization truly ready for
- 17:25an incident response where the data is already
- 17:27gone rather than just encrypted? Because backups
- 17:30don't solve the problem anymore. Exactly. In
- 17:32a double extortion scenario, pristine offline
- 17:35backups will help you restore your systems, but
- 17:39they will not unsteer your data. Right. The data
- 17:42is still out there. Yeah. Your incident response
- 17:44playbook cannot just be an IT recovery manual.
- 17:47It must include legal counsel. public relations
- 17:50strategies, regulatory notification procedures,
- 17:53and clear communication plans for the patients
- 17:56whose data has been compromised. It becomes a
- 17:58whole of business crisis. It really does. The
- 18:00overarching lesson is that proactive defense,
- 18:02buying the hardware keys, segmenting the network,
- 18:04paying for behavioral monitoring is infinitely
- 18:07cheaper and less damaging than trying to manage
- 18:09the fallout of highly sensitive medical records
- 18:11hitting the dark web. It is just a vicious industrialized
- 18:15cycle. And the only way to disrupt it is by making
- 18:17the initial breach too complex. costly, too complex,
- 18:20and too time -consuming for the affiliates to
- 18:22bother with. We have covered a tremendous amount
- 18:25of ground in this session. We really have. To
- 18:27quickly recap our exploration for you, we dissected
- 18:30the March 2026 joint advisory from Five Eyes
- 18:34partners detailing the INC ransom threat. We
- 18:38broke down their ransomware as a service business
- 18:40model, exploring how they utilize initial access
- 18:43brokers to scale attacks against Australian and
- 18:45Pacific critical infrastructure. Right. relying
- 19:07on behavioral monitoring to catch what traditional
- 19:09antivirus misses. The complexity of the threat
- 19:12demands a matching level of sophistication in
- 19:14our defense. And building on everything we've
- 19:16explored, I want to leave you with a final thought
- 19:18to consider. Okay, let's hear it. We spent this
- 19:20session detailing how ransomware groups are successfully
- 19:23franchising their operations, right? They share
- 19:25initial access, lease backend infrastructure,
- 19:27and collaborate to scale their attacks. Yeah,
- 19:30highly collaborative. If the adversaries are
- 19:32collaborating this efficiently, are we doing
- 19:35enough to franchise our defense? How can organizations,
- 19:38particularly within the healthcare sector, better
- 19:40share threat intelligence, behavioral detection
- 19:42rules, and incident response playbooks in real
- 19:45time so that an attempted breach on one regional
- 19:48hospital automatically translates into an impenetrable
- 19:51defense for all the others? Wow, that is a phenomenal
- 19:54challenge to end on. The cybercrime economy is
- 19:57networked, so our defensive posture must be equally
- 20:00collaborative. If you are listening to this session
- 20:02and realize your organization needs to take these
- 20:05warnings to heart, if you need to... ensure your
- 20:07critical infrastructure, your patient data, and
- 20:09your operational resilience are protected against
- 20:12highly motivated threat ecosystems like INC Ransom,
- 20:15you cannot wait for the breach to happen. No,
- 20:17you absolutely cannot. You need to visit www
- 20:20.kinsoft .com .au to discuss your security and
- 20:24IT needs. They have the specialized expertise
- 20:26required to help you build those internal bulkheads,
- 20:29deploy behavioral monitoring, and genuinely secure
- 20:32your environment. Achieving resilience against
- 20:34double extortion is complex. But with the right
- 20:36architectural strategy, it is entirely possible.
- 20:39Thank you so much for joining us on this exploration
- 20:42of the modern threat landscape. We've loved unpacking
- 20:45these insights with you. Stay vigilant, stay
- 20:46secure. And remember, we are no longer defending
- 20:50against isolated hackers. We are defending against
- 20:52an industry. It is time to fortify the network.
- 20:55Catch you next time.