Excite Cyber Threat Intelligence Report – Q1 2026

Share This Post

Q1 2026 has been defined by speed. Storm-1175, a financially motivated affiliate of the Medusa ransomware-as-a-service operation, has emerged as the quarter’s most aggressive threat to Australian businesses, weaponising newly disclosed vulnerabilities in internet-facing systems and moving from initial breach to full ransomware deployment in as little as 24 hours.

The group’s playbook is methodical and proven: exploit a public-facing application, create a local admin account, dump credentials from LSASS, raid Veeam backup databases, then push Medusa ransomware (Gaze.exe) network-wide via PDQ Deployer or Group Policy. Microsoft Threat Intelligence confirmed in April 2026 that Australian organisations are being actively targeted, with healthcare, education, professional services, and financial services bearing the brunt.

More To Explore

cyber-security

Excite Cyber Threat Intelligence Report – Q1 2026

Q1 2026 has been defined by speed. Storm-1175, a financially motivated affiliate of the Medusa ransomware-as-a-service operation, has emerged as the quarter’s most aggressive threat to Australian businesses, weaponising newly disclosed vulnerabilities in internet-facing systems and moving from initial breach to full ransomware deployment in as little as 24 hours.

cyber-security

Excite Cyber ECDC Threat Intelligence Report – Q4 2025

The fourth quarter of 2025 demonstrated an escalating convergence of nation-state espionage, ransomware innovation, and supply-chain exploitation across the Asia–Pacific region. As geopolitical tensions intensify and digital dependencies deepen, threat actors have pivoted from opportunistic attacks to systematic campaigns targeting trust architectures—identities, cloud infrastructure, and third-party integrations that underpin modern enterprise operations.

Enter your details to download your Q1 2026 Threat Intelligence Report