INC Ransom Affiliate Model Enabling Targeting of Critical Networks
ID: f33fe899-dd8c-5354-8cd4-4c3b4e4e1956
STIX ID: report--f33fe899-dd8c-5354-8cd4-4c3b4e4e1956
Date Published: 2026-03-06
Date Updated: 2026-07-26
Author: Australian Cyber Security Centre (ACSC)
INC Ransom (aka Tarnished Scorpion / GOLD IONIC) is a Ransomware-as-a-Service group active since mid-2023 that and its affiliates have targeted organisations—notably health care providers—in Australia, New Zealand and Pacific island states using compromised credentials and exploited public-facing systems to exfiltrate sensitive data and perform double-extortion via a dark web data leak site; the advisory details observed incidents (including the Tonga Ministry of Health), mapped MITRE ATT&CK techniques, IOCs (e.g., ransom notes, file named win.exe), and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
