ANZ threat activity is dominated by identity- and access-driven compromise, with credential stuffing, stolen credentials, and initial-access broker sales recurring across financial services, manufacturing, and mining. Qilin is the most active cross-sector ransomware actor, while the report also highlights state-aligned pre-positioning by Volt Typhoon and Salt Typhoon, plus exploited vulnerabilities such as CVE-2023-20198, CVE-2025-59287, and CVE-2026-41940. #Qilin #VoltTyphoon #SaltTyphoon #CVE-2023-20198 #CVE-2025-59287 #CVE-2026-41940
Keypoints
- Identity and access compromise is the dominant attack surface across ANZ sectors, not novel exploitation.
- Credential stuffing was the clearest confirmed access technique, especially in financial services.
- Qilin is the most active ransomware actor in the report and has the broadest cross-sector footprint.
- Banking stands out for having zero confirmed named ANZ deposit-taking bank victims in the tracked record.
- Mining faces both ransomware pressure and geopolitical risk because of Australia’s critical-minerals position.
- Manufacturing and mining show strong third-party and supply-chain compromise patterns, especially via contractors and suppliers.
- State-sponsored activity by Volt Typhoon and Salt Typhoon is treated as sustained pre-positioning rather than isolated incidents.
MITRE Techniques
- [T1110 ] Brute Force – Used for credential stuffing against financial services accounts, described as ‘credential stuffing the defining technique behind the period’s most significant incident’.
- [T1078 ] Valid Accounts – Access gained through stolen or reused credentials, reflected in ‘compromised credentials’ and ‘stolen credentials’ used across sectors.
- [T1190 ] Exploit Public-Facing Application – Applied to internet-facing systems such as WSUS and cPanel & WHM, described as ‘unauthenticated RCE’ and ‘active exploitation in Australia’.
- [T1133 ] External Remote Services – Used through exploited perimeter and remote-access infrastructure, noted as ‘exploited remote-access infrastructure’ and ‘compromised perimeter systems’.
- [T1486 ] Data Encrypted for Impact – Ransomware operators used encryption and double extortion, described as ‘ransomware / double extortion’.
- [T1071 ] Application Layer Protocol – Implied in sustained access operations over telecom and backbone infrastructure, with ‘backbone/edge router compromise since 2021+’.
- [T1195 ] Supply Chain Compromise – Observed through equipment, engineering, logistics, and IT/technology providers, described as ‘the primary observed pattern’ and ‘dominant route into downstream manufacturing customers’.
- [T1586 ] Compromise Accounts – Underground monetisation of stolen credentials and datasets, reflected in ‘credential collections’ and ‘compromised-access sales’.
- [T1041 ] Exfiltration Over C2 Channel – Supported by double-extortion and leak-site activity, where theft is paired with public posting of data.
- [T1595 ] Active Scanning – Implied by mass exploitation of internet-facing infrastructure and rapid weaponisation of newly disclosed vulnerabilities.
Indicators of Compromise
- [CVE] Exploited vulnerabilities and advisory references – CVE-2023-20198, CVE-2025-59287, and CVE-2026-41940.
- [Malware / web shell] Malware indicators tied to campaign activity – BADCANDY, Carbanak.
- [Threat actor names] Named ransomware and state-linked actors discussed in the report – Qilin, Volt Typhoon, Salt Typhoon, TheGentlemen.
- [Affected products / platforms] Products associated with active exploitation – Cisco IOS XE, Microsoft WSUS, cPanel & WHM.
- [Time-based campaign context] Campaign timing and activity windows – Jul 2025, Oct 2025, 1 May 2026, March 2026.
- [Underground data types] Underground marketplace data categories observed – telephone-record datasets, accounting databases, business-related databases, credential collections.
- [Geopolitical / victim context] Organizations and sectors referenced in confirmed or claimed incidents – Northern Minerals, superannuation funds, mining contractors, manufacturing firms.
Read more: https://www.cyfirma.com/research/cyber-threat-landscape-australia-and-newzealand/