A joint advisory from ACSC, NCSC, and CERT Tonga warns of escalating INC Ransom ransomware attacks targeting organizations in Australia, New Zealand, and Pacific Island states. Active since mid-2023 and believed to be Russia-based, INC Ransom operates as a Ransomware-as-a-Service platform with a distributed affiliate model.
Table of contents
The INC Ransom Affiliate Model and the RaaS EcosystemINC Ransom Incidents in AustraliaHealth Infrastructure Disruption in TongaRansomware Incident in New ZealandTechnical Tactics Used by INC RansomDefensive Measures Recommended by ACSC, NCSC, and CERT TongaGrowing Regional Collaboration Against the INC RansomSort: