2025 Comprehensive Threat Intelligence Assessment
Document Version: 6.0 | Last Updated: 2026-01-14 | Classification: TLP:CLEAR
1. Executive Summary
Qilin and Rhysida pose the greatest dual threat to healthcare systems in the Indo-Pacific region, combining aggressive healthcare targeting with extensive regional operations. The ransomware landscape underwent significant restructuring in 2024-2025 following law enforcement actions against LockBit and ALPHV/BlackCat, with displaced affiliates migrating to RansomHub (now defunct), Qilin, and DragonForce.
Healthcare experienced unprecedented attacks in 2024 with 530+ documented attacks against US healthcare in a 6-month period, resulting in 181 confirmed ransomware incidents involving 25.6 million patient records. The Indo-Pacific region saw parallel escalation: Australia recorded 380+ victims, Japan’s ransomware incidents increased 1.4x in H1 2025, and South Korea experienced a devastating 25-victim campaign in September 2025.
Late 2025 saw the emergence of significant new threats: Kazu (September 2025) demonstrates immediate healthcare focus with attacks on medical platforms across New Zealand, UK, and Texas; Dire Wolf (May 2025) has rapidly expanded to 41+ victims across Asia-Pacific with confirmed healthcare and pharmaceutical targeting; Termite directly exposed Medicare card numbers in the Genea Australia breach.
1.1 Report At-a-Glance
| Category | Summary |
|---|---|
| Highest Priority Threats | Qilin, Rhysida, Kazu, Termite, INC Ransom |
| Threat Type | Ransomware-as-a-Service (RaaS), Double/Triple Extortion |
| Primary Motivation | Financial (ransom + data sale), some state-nexus activity |
| Healthcare Impact | 530+ US attacks (6 months), confirmed patient fatalities, 192.7M records exposed |
| Indo-Pacific Victims | Australia 380+, Japan 68 (H1 2025), South Korea 25+ (Sept 2025), India 362+ |
| Key TTPs | VPN exploitation, social engineering, BYOVD, supply chain attacks |
| Top Mitigation | Patch Ivanti/Fortinet VPNs, phishing-resistant MFA, offline backups, EDR with BYOVD protection |
1.2 Key Takeaways
- Healthcare targeting has become standard practice: Groups like Qilin, Rhysida, INC Ransom, and Kazu dedicate 15-25% of attacks to healthcare with documented patient harm and fatalities.
- Indo-Pacific operations have matured: Qilin’s systematic targeting of Japanese manufacturing and Korean financial services, combined with Dire Wolf’s explicit Asia-Pacific focus and Kazu’s New Zealand healthcare attack, demonstrate regional threat escalation.
- State-nexus convergence: North Korean actors (Moonstone Sleet) operating as Qilin affiliates represent a paradigm shift where nation-state resources enhance ransomware operations.
- Twelve groups demonstrate dual-threat capability: Confirmed healthcare targeting AND Indo-Pacific operations: Qilin, Kazu, Dire Wolf, Termite, Rhysida, Akira, BianLian, Medusa, DragonForce, INC Ransom, Hunters International, LockBit.
2. How Ransomware Attacks Endanger Patients
Ransomware attacks on healthcare organizations translate directly into patient harm through cascading operational failures.
2.1 Attack Progression and Patient Risk
Phase 1 – Reconnaissance (Days to Weeks Before Encryption): Attackers map critical systems including EHR, laboratory information systems, radiology/imaging platforms, pharmacy dispensing systems, and patient monitoring infrastructure. Backup systems are identified for destruction.
Phase 2 – Data Exfiltration (Hours to Days Before Encryption): Modern ransomware groups employ double-extortion tactics, stealing patient data before encrypting systems. Nearly two-thirds of ransomware attacks against healthcare providers simultaneously encrypted and exfiltrated data.
Phase 3 – Encryption and Operational Paralysis: When encryption deploys, healthcare operations collapse within minutes. Without access to EHR, care teams may not know patient medications or allergies. Without imaging, clinicians cannot make diagnoses.
Phase 4 – Ambulance Diversion and Regional Cascade: A 35.2% increase in EMS arrivals at unaffected hospitals occurs during attack phases. Emergency departments at unaffected hospitals experience 15.1% daily census increases.
2.2 Critical System Failures and Patient Impact
| System Disabled | Immediate Patient Impact | Life-Threatening Scenarios |
|---|---|---|
| Electronic Health Records | No access to allergies, medications, history | Wrong medication; missed critical allergies |
| Laboratory Systems | No blood work, cultures, pathology results | Sepsis undetected; wrong blood type transfused |
| Radiology/PACS | No CT, MRI, X-ray, ultrasound | Stroke type unknown; missed internal bleeding |
| Pharmacy Systems | No dispensing, drug interaction checking | Overdoses; dangerous drug combinations |
| Patient Monitoring | No real-time vitals tracking | Cardiac arrests undetected |
| Blood Bank Systems | No crossmatch, no type verification | Fatal transfusion reactions |
2.3 Documented Mortality Impact
Research Finding: In-hospital mortality for patients already hospitalized at a ransomware-attacked hospital increases between 1.28 and 1.87 percentage points, representing a 35.9-55.3% relative increase compared to pre-attack mean. Cardiac arrest rates jump 81% at neighboring facilities during major incidents.
3. Healthcare-Targeting Ransomware Groups
Ransomware groups have abandoned any pretense of ethical boundaries regarding healthcare. After the December 2023 FBI disruption of ALPHV/BlackCat, the group explicitly removed all targeting restrictions, announcing affiliates could “now block hospitals, nuclear power plants, anything, anywhere.”
3.1 Tier 1: Critical Healthcare Threats
| Group | Healthcare % | Notable Healthcare Victims | Assessment |
|---|---|---|---|
| Qilin | 14% | Synnovis/NHS London (patient deaths, $50M demand) | CRITICAL – Confirmed patient fatality |
| Rhysida | 18.5% | Lurie Children’s Hospital ($3.4M demand, 200K children) | CRITICAL – Disrupted pediatric care |
| Termite | Direct health card theft | Genea AU (Medicare cards exposed) | CRITICAL – Medicare card numbers leaked |
| Kazu | Primary target | Doctor Alliance TX (1.2M), ManageMyHealth NZ (108GB) | HIGH – Explicit patient data theft |
| INC Ransom | 21.7% (highest) | NHS Dumfries (3TB), Alder Hey Children’s Hospital | HIGH – Children’s hospitals targeted |
3.2 Tier 2: Significant Healthcare Threats
| Group | Healthcare % | Notable Victims | Assessment |
|---|---|---|---|
| Black Basta | Explicit | Ascension Health (140 hospitals, $1.1B loss) | CRITICAL – Ambulance diversions |
| BianLian | 18.3% | Boston Children’s Health, Texas Retina (312K) | HIGH – Multiple children’s providers |
| Medusa | Significant | Sophiahemmet Hospital, HCRG Care Group UK | HIGH – 300+ critical infra victims |
| LockBit | 17% | 83 confirmed attacks 2024 | HIGH – Claims restrictions but continues |
| Akira | HC3 advisory | 349 disclosed victims 2024 | MEDIUM – Healthcare among key sectors |
| Dire Wolf | Confirmed | Anadolu Hospitals Turkey, pharma/HCIT | MEDIUM-HIGH – Healthcare IT targeting |
| DragonForce | 7% (growing) | Delta County Memorial (148K affected) | MEDIUM – 6 documented healthcare attacks |
4. Indo-Pacific Regional Operations
The Indo-Pacific region experienced dramatic ransomware escalation, with distinct attack patterns emerging across sub-regions. Qilin emerged as the dominant regional threat, recording 8 confirmed Japanese victims in H1 2025 after having zero reported Japan victims in the prior fiscal year.
4.1 Regional Attack Statistics
| Country | Victims (2024-25) | Most Active Groups | Key Sectors |
|---|---|---|---|
| Australia | 380+ | Qilin, BianLian, Akira, DragonForce, Dire Wolf | Critical infrastructure, healthcare |
| Japan | 68 (H1 2025) | Qilin (8), RansomHub (3), Lynx (3), Akira (2) | Manufacturing (18.2%), SMEs (69%) |
| South Korea | 25+ (Sept spike) | Qilin (Korean Leaks), North Korean actors | Financial services, asset mgmt |
| India | 362+ | LockBit (23%), BianLian (17%), BlackCat (12%) | Manufacturing (29%), healthcare (9%) |
| Singapore | 159 | Akira ($1.4M paid), DragonForce, Dire Wolf | Legal, manufacturing (31%) |
| New Zealand | 46+ | DragonForce, Akira, Safepay, Kazu | Healthcare, telecommunications |
| Thailand | Significant | Dire Wolf, 8Base | Manufacturing, packaging |
| Taiwan | Significant | Dire Wolf, Hunters International | Electronics, manufacturing |
5. Dual-Threat Groups: Healthcare + Indo-Pacific
Twelve ransomware groups now demonstrate confirmed activity in both healthcare targeting AND Indo-Pacific regional operations, representing compounded risk for healthcare organizations in the region.
| Group | Healthcare Activity | Indo-Pacific Activity | Assessment |
|---|---|---|---|
| Qilin | Synnovis (patient death); 14% focus | Japan #1 (8); Korea (25); Australia | HIGHEST PRIORITY |
| Kazu | Doctor Alliance (1.2M); ManageMyHealth NZ | NZ healthcare platform; emerging | HIGH PRIORITY |
| Termite | Genea AU (Medicare cards exposed) | Australia direct targeting | HIGH PRIORITY |
| Dire Wolf | Anadolu Hospitals; pharma/HCIT | Singapore, Thailand, Taiwan, AU primary | MODERATE-HIGH |
| Rhysida | 18.5%; Lurie Children’s Hospital | Global operations | HIGH PRIORITY |
| Akira | HC3 advisory; healthcare key sector | Australia (Nissan), Japan, NZ | HIGH PRIORITY |
| BianLian | 18.3%; Boston Children’s Health | Australia CI focus; ACSC advisory | HIGH PRIORITY |
| INC Ransom | 21.7% (highest); NHS attacks | Australia presence | HIGH PRIORITY |
| DragonForce | 7%; Delta County Memorial | AU, NZ, Palau, India | MODERATE-HIGH |
| Medusa | Disproportionate healthcare targeting | Australia, India active | MODERATE-HIGH |
| Hunters Intl | Integris Health (2.4M patients) | Japan, Taiwan, India | MODERATE |
| LockBit | 17% healthcare attacks | Japan, India, Indonesia | MODERATE |
9. Response and Mitigation Playbook
This section provides comprehensive ransomware resilience guidance aligned with the CERT NZ Critical Controls framework. Controls are mapped to the three phases of a ransomware incident lifecycle: Initial Access, Consolidation & Preparation, and Impact on Target.
9.1 CERT NZ Critical Controls Framework
9.1.1 Initial Access Phase Controls
Controls to prevent attackers from gaining initial network access through phishing, valid credentials, password guessing, vulnerability exploitation, and internet-exposed services.
| Control | Implementation Guidance |
|---|---|
| Password Manager | Deploy enterprise password manager; enforce unique passwords per system; integrate with SSO where possible |
| Patching | Prioritize VPN/edge devices (Ivanti, Fortinet, SonicWall); patch within 48 hours for CISA KEV vulnerabilities |
| Multi-Factor Authentication | Implement phishing-resistant MFA (FIDO2) for all VPN, RDP, and administrative access |
| Application Control | Whitelist approved applications; block script execution from user-writable directories |
| Security Awareness | Train staff on phishing recognition; conduct simulated phishing exercises quarterly |
| Logging and Alerting | Enable PowerShell Script Block Logging (Event ID 4104); monitor authentication failures |
| Asset Lifecycle Management | Maintain accurate asset inventory; decommission abandoned systems; audit internet-exposed services |
9.1.2 Consolidation & Preparation Phase Controls
Controls to limit lateral movement, privilege escalation, and command & control after initial compromise.
| Control | Implementation Guidance |
|---|---|
| Patching | Patch internal systems; prioritize AD, database servers, and backup infrastructure |
| Network Segmentation | Isolate clinical systems from administrative networks; segment IoT/OT devices; block SMB/RDP between workstations |
| Principle of Least Privilege | Remove local admin rights; implement tiered administration; use PAM solutions |
| Logging and Alerting | Monitor LSASS access; detect DCSync attacks; alert on backup service termination |
| Multi-Factor Authentication | Require MFA for privileged operations; implement just-in-time access |
| Application Control | Block living-off-the-land binaries (LOLBins); restrict PowerShell to signed scripts |
9.1.3 Impact on Target Phase Controls
| Control | Implementation Guidance |
|---|---|
| Logging and Alerting | Detect mass file modifications; alert on VSS deletion; monitor for encryption patterns |
| Application Control | Block unknown executables; detect BYOVD driver loading; prevent ransomware payloads |
| Backups (3-2-1-1-0) | 3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors in tested restores |
9.2 Credential-Focused Resilience Exercises
Ransomware threat actors leverage compromised credentials for the majority of their initial entry and lateral movement vectors.
9.2.1 Organization-Wide Credential Reset
- Conduct periodic credential rotation exercises (quarterly recommended for privileged accounts)
- Prioritize service accounts, administrative accounts, and accounts with VPN/remote access
- Deploy LAPS (Local Administrator Password Solution) to randomize local admin passwords
- Review and disable dormant accounts (no login > 90 days)
9.2.2 Have I Been Pwned Integration
- Distribute guidance for all staff to check personal, home, and family credentials at haveibeenpwned.com
- Integrate Pwned Passwords API into Active Directory password policies (free, uses k-anonymity)
- Subscribe to domain monitoring ($3.25/month) to alert when employee credentials appear in breaches
- Provide family cybersecurity guide covering password managers, MFA, and breach monitoring
9.2.3 MFA Deployment Review
- Audit MFA coverage: Identify all accounts without MFA enabled
- Review MFA logs: Check for unusual error rates indicating bypass attempts or MFA fatigue attacks
- Enable number matching: Microsoft Authenticator number matching prevents push notification fatigue
- Upgrade high-risk accounts: Deploy phishing-resistant MFA (FIDO2 hardware keys)
- Monitor for AiTM: Watch for Adversary-in-the-Middle proxy indicators in authentication logs
9.3 Protective DNS with Logging and Alerting
Protective DNS transforms the DNS resolver into a security tool, providing detection and blocking capabilities across all phases of a ransomware attack.
9.3.1 Strategic Value of Protective DNS
- Blocks C2 communications: Prevents malware from reaching command servers even after execution
- Detects lateral movement: Devices have predictable DNS patterns; threat actor activity creates anomalies
- Blocks data exfiltration: Identifies DNS tunneling and connections to known exfiltration sites
- Provides hunting telemetry: DNS logs reveal threat actor reconnaissance and infrastructure
9.3.2 Enterprise-Wide DNS Coverage
Deploy Protective DNS across ALL network segments and device types:
- Workstations and servers: Standard IT infrastructure
- IoT devices: Cameras, sensors, badge readers, environmental controls
- Conference room equipment: Smart TVs, video conferencing systems, digital signage
- Data center infrastructure: Hypervisors, storage arrays, management interfaces
- OT systems: Industrial control systems, building management systems
- Medical equipment: Connected diagnostic devices, infusion pumps, patient monitors
9.3.3 Protective DNS Solutions
Organizations should seek Protective DNS solutions that include logging capabilities. DNS query logs provide critical forensic evidence during incident response and enable proactive threat hunting. Solutions vary from free open-source options to commercial platforms with rich analytics.
DNS RPZ (Response Policy Zone) feeds provide blocklists that work with all open-source DNS resolver solutions including BIND, Unbound, and PowerDNS. This enables organizations to leverage threat intelligence feeds with existing infrastructure.
Free Protective DNS Services:
| Solution | Cost | Key Features |
|---|---|---|
| Quad9 (9.9.9.9) | Free | 20+ threat feeds; 2.7B queries blocked H2 2024; DoH/DoT support; logging via local resolver |
| Cloudflare Gateway | Free (50 users) | DNS filtering with logging dashboard; WARP client for roaming devices |
| CISA Protective DNS | Free (eligible) | US government-grade threat intel for critical infrastructure organizations |
Commercial Protective DNS Solutions:
| Solution | Type | Key Features |
|---|---|---|
| Infoblox | Enterprise DNS Security | Rich forensics and analytics; integrated DDI platform; threat intelligence |
| ThreatStop | Threat Intel Service | Customized blocklists for Protective DNS AND edge network ACLs; unified policy |
| Cisco Umbrella | Cloud DNS Security | Global threat intelligence; detailed logging; roaming client support |
| Akamai ETP | Enterprise Threat Protection | DNS and proxy-based protection; SIA integration; advanced analytics |
Related Network Security Services (ACL-Based, Not DNS):
| Solution | Type | Key Features |
|---|---|---|
| NCSC Malware Free Networks | ACL/Firewall Feed | NZ government threat intel via STIX/TAXII; ISP/firewall integration; 400M+ events blocked. Note: This is an ACL solution, not a DNS resolver blocklist. |
Implementation: Configure Protective DNS as upstream resolver for all internal DNS servers. For organizations using open-source resolvers, subscribe to DNS RPZ feeds from threat intelligence providers. Ensure DNS query logging is enabled and forwarded to SIEM for security monitoring and forensic analysis.
9.4 Shadowserver Foundation Daily Reports
The Shadowserver Foundation provides free daily vulnerability and threat reports offering an outside-in view of your attack surface.
9.4.1 Value of Shadowserver Reports
- Identifies internet-exposed vulnerabilities visible to threat actors
- Reports on compromised hosts, C2 activity, and malware infections in your IP ranges
- Alliance of National CSIRTs, commercial security companies, and research organizations
- Free service supported by grants and donations—no cost to organizations
9.4.2 Enrollment for Daily Reports
Register your organization’s IP ranges at shadowserver.org to receive automated daily notifications of:
- Exposed RDP, SMB, and vulnerable VPN appliances
- Known malware infections and botnet participation
- Misconfigured services and vulnerable software versions
- Compromised devices participating in DDoS amplification
9.4.3 Public Mailing List Subscription
NOC, SOC, and cybersecurity personnel should subscribe to Shadowserver’s public alert mailing list:
Method 1: Email Subscription
- Compose a new email to: public-request@list.shadowserver.org
- Set the subject line to: join
- Send the email (no body text required)
Method 2: Web Subscription
- Visit: https://mail.shadowserver.org/mailman/listinfo/public
- Follow the on-page instructions to complete enrollment
Note: The public mailing list has low traffic and is used primarily for service announcements. More detailed operational discussions occur in TLP:AMBER+STRICT Shadowserver Alliance channels available to member organizations.
9.5 Network Visibility: Ingress/Egress NetFlow
Deploy NetFlow/IPFIX collection on network edge devices to detect data exfiltration, C2 beaconing, and anomalous traffic patterns.
- Configure NetFlow export on border routers and firewalls
- Establish baselines for normal traffic patterns by device type and network segment
- Alert on long-duration flows and unusually large data transfers indicating exfiltration
- Integrate with SIEM for correlation with endpoint and DNS telemetry
- Use tools like Zeek, Elastic NetFlow, or commercial NDR solutions for analysis
9.6 Immediate Response Actions (0-4 Hours)
- Network Isolation: Disconnect affected systems; block known C2 IPs at firewall
- Account Security: Reset all privileged account passwords; disable compromised accounts
- Evidence Preservation: Capture memory dumps, disk images from key systems
- Communication: Activate incident response team; notify leadership
- Threat Hunting: Deploy IOCs to SIEM/EDR platforms immediately
9.7 Critical Patches
| CVE | Product/Notes |
|---|---|
| CVE-2023-46805, CVE-2024-21887 | Ivanti VPN – Primary exploitation vector |
| CVE-2024-57726/27/28 | SimpleHelp RMM – DragonForce exploitation |
| CVE-2024-40766 | SonicWall SSL VPN – Akira, Fog exploitation |
| CVE-2023-27532 | Veeam – Qilin, Dire Wolf targeting backups |
| CVE-2021-44228 | Log4Shell – Still actively exploited |
9.8 Strategic Security Controls
- Implement phishing-resistant MFA (FIDO2) for all administrative accounts and VPN access
- Deploy EDR with BYOVD protection – critical for detecting DragonForce and similar groups
- Enable comprehensive PowerShell logging including script block logging (Event ID 4104)
- Network segmentation to limit lateral movement, especially for clinical and IoT systems
- Maintain offline, immutable backups with tested restoration procedures (3-2-1-1-0 rule)
- Staff training on social engineering particularly help desk manipulation (Scattered Spider TTPs)
- Deploy Canary Tokens and honeypots in backup directories and administrative shares for early detection
10. Ransomware Intelligence Resources
10.1 Leak Site Aggregators
| Resource | URL | Key Features |
|---|---|---|
| RansomLook | https://www.ransomlook.io/ | 524+ groups, REST API |
| ransomwatch | https://ransomwatch.telemetry.ltd/ | 216+ groups, JSON API |
| Ransomware.live | https://www.ransomware.live/ | Live victim feed |
| Halcyon Attacks | https://www.halcyon.ai/attacks | Attack database |
10.2 IOC and Malware Repositories
| Resource | URL | Key Features |
|---|---|---|
| ThreatFox | https://threatfox.abuse.ch/ | 1.6M+ IOCs, REST API |
| MalwareBazaar | https://bazaar.abuse.ch/ | Vetted samples, YARA |
| URLhaus | https://urlhaus.abuse.ch/ | 3.65M+ malware URLs |
| vx-underground | https://vx-underground.org/ | 35M+ samples |
10.3 Ransomware Recovery Resources
- ID Ransomware: https://id-ransomware.malwarehunterteam.com/ (1,179+ variants)
- No More Ransom: https://www.nomoreransom.org/ (170+ free decryptors)
- Kaspersky No Ransom: https://noransom.kaspersky.com/
12. Conclusion and Priority Actions
The 2024-2025 ransomware landscape demonstrates three critical developments requiring immediate organizational response:
First, healthcare targeting has become standard practice rather than exception. Groups like Qilin, Rhysida, INC Ransom, Termite, and emerging actor Kazu dedicate 15-25% of attacks to healthcare with documented patient harm and fatalities.
Second, Indo-Pacific operations have matured beyond opportunistic attacks to sustained campaigns. Qilin’s systematic targeting of Japanese manufacturing and Korean financial services, combined with Dire Wolf’s explicit Asia-Pacific focus and Kazu’s New Zealand healthcare attack, demonstrate regional threat escalation.
Third, the emergence of Kazu, Dire Wolf, and Termite in 2025 demonstrates the ransomware threat continues to proliferate. The state-nexus convergence with North Korean actors operating as Qilin affiliates represents a paradigm shift where nation-state resources enhance ransomware operations.
Defensive Prioritization
- HIGHEST PRIORITY: Qilin, Termite, Kazu – Confirmed healthcare targeting with Indo-Pacific presence and demonstrated patient harm
- HIGH PRIORITY: Rhysida, INC Ransom, Akira, BianLian – Heavy healthcare focus with regional operations
- MODERATE-HIGH: Dire Wolf, DragonForce, Medusa – Emerging regional threats with healthcare capability
- EMERGING WATCH: NightSpire, Sarcoma – Limited data but appearing in APAC tracking
Organizations in Indo-Pacific healthcare sectors face compounded risk from twelve groups demonstrating dual-threat capability. Immediate implementation of detection rules, IOC monitoring, and strategic security controls outlined in this report is essential for organizational resilience.
— END OF REPORT —
Document Version 6.0 | Last Updated: 2026-01-14 | Classification: TLP:CLEAR

