Ransomware Threat Actors Targeting Healthcare and the Indo-Pacific Region

2025 Comprehensive Threat Intelligence Assessment

Document Version: 6.0 | Last Updated: 2026-01-14 | Classification: TLP:CLEAR


1. Executive Summary

Qilin and Rhysida pose the greatest dual threat to healthcare systems in the Indo-Pacific region, combining aggressive healthcare targeting with extensive regional operations. The ransomware landscape underwent significant restructuring in 2024-2025 following law enforcement actions against LockBit and ALPHV/BlackCat, with displaced affiliates migrating to RansomHub (now defunct), Qilin, and DragonForce.

Healthcare experienced unprecedented attacks in 2024 with 530+ documented attacks against US healthcare in a 6-month period, resulting in 181 confirmed ransomware incidents involving 25.6 million patient records. The Indo-Pacific region saw parallel escalation: Australia recorded 380+ victims, Japan’s ransomware incidents increased 1.4x in H1 2025, and South Korea experienced a devastating 25-victim campaign in September 2025.

Late 2025 saw the emergence of significant new threats: Kazu (September 2025) demonstrates immediate healthcare focus with attacks on medical platforms across New Zealand, UK, and Texas; Dire Wolf (May 2025) has rapidly expanded to 41+ victims across Asia-Pacific with confirmed healthcare and pharmaceutical targeting; Termite directly exposed Medicare card numbers in the Genea Australia breach.

1.1 Report At-a-Glance

Category Summary
Highest Priority Threats Qilin, Rhysida, Kazu, Termite, INC Ransom
Threat Type Ransomware-as-a-Service (RaaS), Double/Triple Extortion
Primary Motivation Financial (ransom + data sale), some state-nexus activity
Healthcare Impact 530+ US attacks (6 months), confirmed patient fatalities, 192.7M records exposed
Indo-Pacific Victims Australia 380+, Japan 68 (H1 2025), South Korea 25+ (Sept 2025), India 362+
Key TTPs VPN exploitation, social engineering, BYOVD, supply chain attacks
Top Mitigation Patch Ivanti/Fortinet VPNs, phishing-resistant MFA, offline backups, EDR with BYOVD protection

1.2 Key Takeaways

  1. Healthcare targeting has become standard practice: Groups like Qilin, Rhysida, INC Ransom, and Kazu dedicate 15-25% of attacks to healthcare with documented patient harm and fatalities.
  2. Indo-Pacific operations have matured: Qilin’s systematic targeting of Japanese manufacturing and Korean financial services, combined with Dire Wolf’s explicit Asia-Pacific focus and Kazu’s New Zealand healthcare attack, demonstrate regional threat escalation.
  3. State-nexus convergence: North Korean actors (Moonstone Sleet) operating as Qilin affiliates represent a paradigm shift where nation-state resources enhance ransomware operations.
  4. Twelve groups demonstrate dual-threat capability: Confirmed healthcare targeting AND Indo-Pacific operations: Qilin, Kazu, Dire Wolf, Termite, Rhysida, Akira, BianLian, Medusa, DragonForce, INC Ransom, Hunters International, LockBit.

2. How Ransomware Attacks Endanger Patients

Ransomware attacks on healthcare organizations translate directly into patient harm through cascading operational failures.

2.1 Attack Progression and Patient Risk

Phase 1 – Reconnaissance (Days to Weeks Before Encryption): Attackers map critical systems including EHR, laboratory information systems, radiology/imaging platforms, pharmacy dispensing systems, and patient monitoring infrastructure. Backup systems are identified for destruction.

Phase 2 – Data Exfiltration (Hours to Days Before Encryption): Modern ransomware groups employ double-extortion tactics, stealing patient data before encrypting systems. Nearly two-thirds of ransomware attacks against healthcare providers simultaneously encrypted and exfiltrated data.

Phase 3 – Encryption and Operational Paralysis: When encryption deploys, healthcare operations collapse within minutes. Without access to EHR, care teams may not know patient medications or allergies. Without imaging, clinicians cannot make diagnoses.

Phase 4 – Ambulance Diversion and Regional Cascade: A 35.2% increase in EMS arrivals at unaffected hospitals occurs during attack phases. Emergency departments at unaffected hospitals experience 15.1% daily census increases.

2.2 Critical System Failures and Patient Impact

System Disabled Immediate Patient Impact Life-Threatening Scenarios
Electronic Health Records No access to allergies, medications, history Wrong medication; missed critical allergies
Laboratory Systems No blood work, cultures, pathology results Sepsis undetected; wrong blood type transfused
Radiology/PACS No CT, MRI, X-ray, ultrasound Stroke type unknown; missed internal bleeding
Pharmacy Systems No dispensing, drug interaction checking Overdoses; dangerous drug combinations
Patient Monitoring No real-time vitals tracking Cardiac arrests undetected
Blood Bank Systems No crossmatch, no type verification Fatal transfusion reactions

2.3 Documented Mortality Impact

Research Finding: In-hospital mortality for patients already hospitalized at a ransomware-attacked hospital increases between 1.28 and 1.87 percentage points, representing a 35.9-55.3% relative increase compared to pre-attack mean. Cardiac arrest rates jump 81% at neighboring facilities during major incidents.


3. Healthcare-Targeting Ransomware Groups

Ransomware groups have abandoned any pretense of ethical boundaries regarding healthcare. After the December 2023 FBI disruption of ALPHV/BlackCat, the group explicitly removed all targeting restrictions, announcing affiliates could “now block hospitals, nuclear power plants, anything, anywhere.”

3.1 Tier 1: Critical Healthcare Threats

Group Healthcare % Notable Healthcare Victims Assessment
Qilin 14% Synnovis/NHS London (patient deaths, $50M demand) CRITICAL – Confirmed patient fatality
Rhysida 18.5% Lurie Children’s Hospital ($3.4M demand, 200K children) CRITICAL – Disrupted pediatric care
Termite Direct health card theft Genea AU (Medicare cards exposed) CRITICAL – Medicare card numbers leaked
Kazu Primary target Doctor Alliance TX (1.2M), ManageMyHealth NZ (108GB) HIGH – Explicit patient data theft
INC Ransom 21.7% (highest) NHS Dumfries (3TB), Alder Hey Children’s Hospital HIGH – Children’s hospitals targeted

3.2 Tier 2: Significant Healthcare Threats

Group Healthcare % Notable Victims Assessment
Black Basta Explicit Ascension Health (140 hospitals, $1.1B loss) CRITICAL – Ambulance diversions
BianLian 18.3% Boston Children’s Health, Texas Retina (312K) HIGH – Multiple children’s providers
Medusa Significant Sophiahemmet Hospital, HCRG Care Group UK HIGH – 300+ critical infra victims
LockBit 17% 83 confirmed attacks 2024 HIGH – Claims restrictions but continues
Akira HC3 advisory 349 disclosed victims 2024 MEDIUM – Healthcare among key sectors
Dire Wolf Confirmed Anadolu Hospitals Turkey, pharma/HCIT MEDIUM-HIGH – Healthcare IT targeting
DragonForce 7% (growing) Delta County Memorial (148K affected) MEDIUM – 6 documented healthcare attacks

4. Indo-Pacific Regional Operations

The Indo-Pacific region experienced dramatic ransomware escalation, with distinct attack patterns emerging across sub-regions. Qilin emerged as the dominant regional threat, recording 8 confirmed Japanese victims in H1 2025 after having zero reported Japan victims in the prior fiscal year.

4.1 Regional Attack Statistics

Country Victims (2024-25) Most Active Groups Key Sectors
Australia 380+ Qilin, BianLian, Akira, DragonForce, Dire Wolf Critical infrastructure, healthcare
Japan 68 (H1 2025) Qilin (8), RansomHub (3), Lynx (3), Akira (2) Manufacturing (18.2%), SMEs (69%)
South Korea 25+ (Sept spike) Qilin (Korean Leaks), North Korean actors Financial services, asset mgmt
India 362+ LockBit (23%), BianLian (17%), BlackCat (12%) Manufacturing (29%), healthcare (9%)
Singapore 159 Akira ($1.4M paid), DragonForce, Dire Wolf Legal, manufacturing (31%)
New Zealand 46+ DragonForce, Akira, Safepay, Kazu Healthcare, telecommunications
Thailand Significant Dire Wolf, 8Base Manufacturing, packaging
Taiwan Significant Dire Wolf, Hunters International Electronics, manufacturing

5. Dual-Threat Groups: Healthcare + Indo-Pacific

Twelve ransomware groups now demonstrate confirmed activity in both healthcare targeting AND Indo-Pacific regional operations, representing compounded risk for healthcare organizations in the region.

Group Healthcare Activity Indo-Pacific Activity Assessment
Qilin Synnovis (patient death); 14% focus Japan #1 (8); Korea (25); Australia HIGHEST PRIORITY
Kazu Doctor Alliance (1.2M); ManageMyHealth NZ NZ healthcare platform; emerging HIGH PRIORITY
Termite Genea AU (Medicare cards exposed) Australia direct targeting HIGH PRIORITY
Dire Wolf Anadolu Hospitals; pharma/HCIT Singapore, Thailand, Taiwan, AU primary MODERATE-HIGH
Rhysida 18.5%; Lurie Children’s Hospital Global operations HIGH PRIORITY
Akira HC3 advisory; healthcare key sector Australia (Nissan), Japan, NZ HIGH PRIORITY
BianLian 18.3%; Boston Children’s Health Australia CI focus; ACSC advisory HIGH PRIORITY
INC Ransom 21.7% (highest); NHS attacks Australia presence HIGH PRIORITY
DragonForce 7%; Delta County Memorial AU, NZ, Palau, India MODERATE-HIGH
Medusa Disproportionate healthcare targeting Australia, India active MODERATE-HIGH
Hunters Intl Integris Health (2.4M patients) Japan, Taiwan, India MODERATE
LockBit 17% healthcare attacks Japan, India, Indonesia MODERATE

9. Response and Mitigation Playbook

This section provides comprehensive ransomware resilience guidance aligned with the CERT NZ Critical Controls framework. Controls are mapped to the three phases of a ransomware incident lifecycle: Initial Access, Consolidation & Preparation, and Impact on Target.

9.1 CERT NZ Critical Controls Framework

9.1.1 Initial Access Phase Controls

Controls to prevent attackers from gaining initial network access through phishing, valid credentials, password guessing, vulnerability exploitation, and internet-exposed services.

Control Implementation Guidance
Password Manager Deploy enterprise password manager; enforce unique passwords per system; integrate with SSO where possible
Patching Prioritize VPN/edge devices (Ivanti, Fortinet, SonicWall); patch within 48 hours for CISA KEV vulnerabilities
Multi-Factor Authentication Implement phishing-resistant MFA (FIDO2) for all VPN, RDP, and administrative access
Application Control Whitelist approved applications; block script execution from user-writable directories
Security Awareness Train staff on phishing recognition; conduct simulated phishing exercises quarterly
Logging and Alerting Enable PowerShell Script Block Logging (Event ID 4104); monitor authentication failures
Asset Lifecycle Management Maintain accurate asset inventory; decommission abandoned systems; audit internet-exposed services

9.1.2 Consolidation & Preparation Phase Controls

Controls to limit lateral movement, privilege escalation, and command & control after initial compromise.

Control Implementation Guidance
Patching Patch internal systems; prioritize AD, database servers, and backup infrastructure
Network Segmentation Isolate clinical systems from administrative networks; segment IoT/OT devices; block SMB/RDP between workstations
Principle of Least Privilege Remove local admin rights; implement tiered administration; use PAM solutions
Logging and Alerting Monitor LSASS access; detect DCSync attacks; alert on backup service termination
Multi-Factor Authentication Require MFA for privileged operations; implement just-in-time access
Application Control Block living-off-the-land binaries (LOLBins); restrict PowerShell to signed scripts

9.1.3 Impact on Target Phase Controls

Control Implementation Guidance
Logging and Alerting Detect mass file modifications; alert on VSS deletion; monitor for encryption patterns
Application Control Block unknown executables; detect BYOVD driver loading; prevent ransomware payloads
Backups (3-2-1-1-0) 3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors in tested restores

9.2 Credential-Focused Resilience Exercises

Ransomware threat actors leverage compromised credentials for the majority of their initial entry and lateral movement vectors.

9.2.1 Organization-Wide Credential Reset

  • Conduct periodic credential rotation exercises (quarterly recommended for privileged accounts)
  • Prioritize service accounts, administrative accounts, and accounts with VPN/remote access
  • Deploy LAPS (Local Administrator Password Solution) to randomize local admin passwords
  • Review and disable dormant accounts (no login > 90 days)

9.2.2 Have I Been Pwned Integration

  • Distribute guidance for all staff to check personal, home, and family credentials at haveibeenpwned.com
  • Integrate Pwned Passwords API into Active Directory password policies (free, uses k-anonymity)
  • Subscribe to domain monitoring ($3.25/month) to alert when employee credentials appear in breaches
  • Provide family cybersecurity guide covering password managers, MFA, and breach monitoring

9.2.3 MFA Deployment Review

  • Audit MFA coverage: Identify all accounts without MFA enabled
  • Review MFA logs: Check for unusual error rates indicating bypass attempts or MFA fatigue attacks
  • Enable number matching: Microsoft Authenticator number matching prevents push notification fatigue
  • Upgrade high-risk accounts: Deploy phishing-resistant MFA (FIDO2 hardware keys)
  • Monitor for AiTM: Watch for Adversary-in-the-Middle proxy indicators in authentication logs

9.3 Protective DNS with Logging and Alerting

Protective DNS transforms the DNS resolver into a security tool, providing detection and blocking capabilities across all phases of a ransomware attack.

9.3.1 Strategic Value of Protective DNS

  • Blocks C2 communications: Prevents malware from reaching command servers even after execution
  • Detects lateral movement: Devices have predictable DNS patterns; threat actor activity creates anomalies
  • Blocks data exfiltration: Identifies DNS tunneling and connections to known exfiltration sites
  • Provides hunting telemetry: DNS logs reveal threat actor reconnaissance and infrastructure

9.3.2 Enterprise-Wide DNS Coverage

Deploy Protective DNS across ALL network segments and device types:

  • Workstations and servers: Standard IT infrastructure
  • IoT devices: Cameras, sensors, badge readers, environmental controls
  • Conference room equipment: Smart TVs, video conferencing systems, digital signage
  • Data center infrastructure: Hypervisors, storage arrays, management interfaces
  • OT systems: Industrial control systems, building management systems
  • Medical equipment: Connected diagnostic devices, infusion pumps, patient monitors

9.3.3 Protective DNS Solutions

Organizations should seek Protective DNS solutions that include logging capabilities. DNS query logs provide critical forensic evidence during incident response and enable proactive threat hunting. Solutions vary from free open-source options to commercial platforms with rich analytics.

DNS RPZ (Response Policy Zone) feeds provide blocklists that work with all open-source DNS resolver solutions including BIND, Unbound, and PowerDNS. This enables organizations to leverage threat intelligence feeds with existing infrastructure.

Free Protective DNS Services:

Solution Cost Key Features
Quad9 (9.9.9.9) Free 20+ threat feeds; 2.7B queries blocked H2 2024; DoH/DoT support; logging via local resolver
Cloudflare Gateway Free (50 users) DNS filtering with logging dashboard; WARP client for roaming devices
CISA Protective DNS Free (eligible) US government-grade threat intel for critical infrastructure organizations

Commercial Protective DNS Solutions:

Solution Type Key Features
Infoblox Enterprise DNS Security Rich forensics and analytics; integrated DDI platform; threat intelligence
ThreatStop Threat Intel Service Customized blocklists for Protective DNS AND edge network ACLs; unified policy
Cisco Umbrella Cloud DNS Security Global threat intelligence; detailed logging; roaming client support
Akamai ETP Enterprise Threat Protection DNS and proxy-based protection; SIA integration; advanced analytics

Related Network Security Services (ACL-Based, Not DNS):

Solution Type Key Features
NCSC Malware Free Networks ACL/Firewall Feed NZ government threat intel via STIX/TAXII; ISP/firewall integration; 400M+ events blocked. Note: This is an ACL solution, not a DNS resolver blocklist.

Implementation: Configure Protective DNS as upstream resolver for all internal DNS servers. For organizations using open-source resolvers, subscribe to DNS RPZ feeds from threat intelligence providers. Ensure DNS query logging is enabled and forwarded to SIEM for security monitoring and forensic analysis.

9.4 Shadowserver Foundation Daily Reports

The Shadowserver Foundation provides free daily vulnerability and threat reports offering an outside-in view of your attack surface.

9.4.1 Value of Shadowserver Reports

  • Identifies internet-exposed vulnerabilities visible to threat actors
  • Reports on compromised hosts, C2 activity, and malware infections in your IP ranges
  • Alliance of National CSIRTs, commercial security companies, and research organizations
  • Free service supported by grants and donations—no cost to organizations

9.4.2 Enrollment for Daily Reports

Register your organization’s IP ranges at shadowserver.org to receive automated daily notifications of:

  • Exposed RDP, SMB, and vulnerable VPN appliances
  • Known malware infections and botnet participation
  • Misconfigured services and vulnerable software versions
  • Compromised devices participating in DDoS amplification

9.4.3 Public Mailing List Subscription

NOC, SOC, and cybersecurity personnel should subscribe to Shadowserver’s public alert mailing list:

Method 1: Email Subscription

  1. Compose a new email to: public-request@list.shadowserver.org
  2. Set the subject line to: join
  3. Send the email (no body text required)

Method 2: Web Subscription

  1. Visit: https://mail.shadowserver.org/mailman/listinfo/public
  2. Follow the on-page instructions to complete enrollment

Note: The public mailing list has low traffic and is used primarily for service announcements. More detailed operational discussions occur in TLP:AMBER+STRICT Shadowserver Alliance channels available to member organizations.

9.5 Network Visibility: Ingress/Egress NetFlow

Deploy NetFlow/IPFIX collection on network edge devices to detect data exfiltration, C2 beaconing, and anomalous traffic patterns.

  • Configure NetFlow export on border routers and firewalls
  • Establish baselines for normal traffic patterns by device type and network segment
  • Alert on long-duration flows and unusually large data transfers indicating exfiltration
  • Integrate with SIEM for correlation with endpoint and DNS telemetry
  • Use tools like Zeek, Elastic NetFlow, or commercial NDR solutions for analysis

9.6 Immediate Response Actions (0-4 Hours)

  1. Network Isolation: Disconnect affected systems; block known C2 IPs at firewall
  2. Account Security: Reset all privileged account passwords; disable compromised accounts
  3. Evidence Preservation: Capture memory dumps, disk images from key systems
  4. Communication: Activate incident response team; notify leadership
  5. Threat Hunting: Deploy IOCs to SIEM/EDR platforms immediately

9.7 Critical Patches

CVE Product/Notes
CVE-2023-46805, CVE-2024-21887 Ivanti VPN – Primary exploitation vector
CVE-2024-57726/27/28 SimpleHelp RMM – DragonForce exploitation
CVE-2024-40766 SonicWall SSL VPN – Akira, Fog exploitation
CVE-2023-27532 Veeam – Qilin, Dire Wolf targeting backups
CVE-2021-44228 Log4Shell – Still actively exploited

9.8 Strategic Security Controls

  • Implement phishing-resistant MFA (FIDO2) for all administrative accounts and VPN access
  • Deploy EDR with BYOVD protection – critical for detecting DragonForce and similar groups
  • Enable comprehensive PowerShell logging including script block logging (Event ID 4104)
  • Network segmentation to limit lateral movement, especially for clinical and IoT systems
  • Maintain offline, immutable backups with tested restoration procedures (3-2-1-1-0 rule)
  • Staff training on social engineering particularly help desk manipulation (Scattered Spider TTPs)
  • Deploy Canary Tokens and honeypots in backup directories and administrative shares for early detection

10. Ransomware Intelligence Resources

10.1 Leak Site Aggregators

Resource URL Key Features
RansomLook https://www.ransomlook.io/ 524+ groups, REST API
ransomwatch https://ransomwatch.telemetry.ltd/ 216+ groups, JSON API
Ransomware.live https://www.ransomware.live/ Live victim feed
Halcyon Attacks https://www.halcyon.ai/attacks Attack database

10.2 IOC and Malware Repositories

Resource URL Key Features
ThreatFox https://threatfox.abuse.ch/ 1.6M+ IOCs, REST API
MalwareBazaar https://bazaar.abuse.ch/ Vetted samples, YARA
URLhaus https://urlhaus.abuse.ch/ 3.65M+ malware URLs
vx-underground https://vx-underground.org/ 35M+ samples

10.3 Ransomware Recovery Resources

  • ID Ransomware: https://id-ransomware.malwarehunterteam.com/ (1,179+ variants)
  • No More Ransom: https://www.nomoreransom.org/ (170+ free decryptors)
  • Kaspersky No Ransom: https://noransom.kaspersky.com/

12. Conclusion and Priority Actions

The 2024-2025 ransomware landscape demonstrates three critical developments requiring immediate organizational response:

First, healthcare targeting has become standard practice rather than exception. Groups like Qilin, Rhysida, INC Ransom, Termite, and emerging actor Kazu dedicate 15-25% of attacks to healthcare with documented patient harm and fatalities.

Second, Indo-Pacific operations have matured beyond opportunistic attacks to sustained campaigns. Qilin’s systematic targeting of Japanese manufacturing and Korean financial services, combined with Dire Wolf’s explicit Asia-Pacific focus and Kazu’s New Zealand healthcare attack, demonstrate regional threat escalation.

Third, the emergence of Kazu, Dire Wolf, and Termite in 2025 demonstrates the ransomware threat continues to proliferate. The state-nexus convergence with North Korean actors operating as Qilin affiliates represents a paradigm shift where nation-state resources enhance ransomware operations.

Defensive Prioritization

  1. HIGHEST PRIORITY: Qilin, Termite, Kazu – Confirmed healthcare targeting with Indo-Pacific presence and demonstrated patient harm
  2. HIGH PRIORITY: Rhysida, INC Ransom, Akira, BianLian – Heavy healthcare focus with regional operations
  3. MODERATE-HIGH: Dire Wolf, DragonForce, Medusa – Emerging regional threats with healthcare capability
  4. EMERGING WATCH: NightSpire, Sarcoma – Limited data but appearing in APAC tracking

Organizations in Indo-Pacific healthcare sectors face compounded risk from twelve groups demonstrating dual-threat capability. Immediate implementation of detection rules, IOC monitoring, and strategic security controls outlined in this report is essential for organizational resilience.


— END OF REPORT —

Document Version 6.0 | Last Updated: 2026-01-14 | Classification: TLP:CLEAR