Skip to main content

Cyber security articles

What ASD’s 2024–25 threat year means for six kinds of specialist work

Ransomware share held, DDoS surged, legacy technology and third-party risk are official ASD actions. How that maps to reverse engineering, malware analysis, code review, testing, audit and recovery, using ACSC, ASD and (ISC)² terms.

ASD’s ACSC closed FY2024–25 with more than 1,200 cyber security incidents responded to (up 11%), more than 84,700 cybercrime reports, and a ransomware share that did not fall. Average self-reported losses rose, 14% for small business, 219% for large. This article maps that official year, and a handful of public Australian and global cases, onto the six kinds of authorised work this practice actually sells. It is not a claim that we worked those incidents.

The terms we are using

ASD’s ACSC is the Australian Government’s lead for cyber security. A cyber security incident is an unwanted or unexpected event affecting confidentiality, integrity or availability. A malicious cyber actor may be a cybercriminal or a state-sponsored actor. The ISM is the Information Security Manual; the Essential Eight is eight prioritised mitigations derived from it. (ISC)²’s CISSP student glossary supplies the professional vocabulary we use alongside that: asset, attack surface, least privilege, authorization, due care, black-box testing, business continuity and disaster recovery. We do not mix those terms loosely.

Malware analysis and threat intelligence

Eleven per cent of incidents ASD responded to included ransomware, unchanged year on year. The precursor is still malware that harvests credentials. After the 19 July 2024 CrowdStrike outage, ASD found hundreds of fake CrowdStrike sites and shared indicators of compromise on CTIS. That is the difference between a public detection ratio and private analysis: IOCs you can hunt, on an artefact you did not broadcast. Supply-chain worms (Shai-Hulud on npm; Glassworm across VS Code, npm and PyPI) make “is this package malicious?” a specialist question again.

Software and firmware reverse engineering

ASD’s four recommended actions for 2024–25 include replacing legacy technology. Ivanti Connect Secure’s CVE-2025-0282, exploited as a zero-day from mid-December 2024, included malware that faked a successful firmware upgrade. MOVEit Transfer’s 2023 SQL injection and later critical waves through 2026 showed a whole product class, managed file transfer, remaining an unowned attack surface. If you do not have source, you cannot patch what you cannot see. Reverse engineering documents behaviour. It does not resurrect original source.

Secure code review and codebase hardening

Third-party risk is the second of ASD’s four actions. Latitude’s 2023 breach, one stolen credential, records back to 2005, is the public reminder that retention, authorisation and least privilege are design defects, not scanner findings. Package-registry worms mean a clean build today can ship someone else’s malware tomorrow. (ISC)² is explicit: different testing methods find different vulnerability types. Manual review is due care; unreviewed SAST output is not.

Penetration testing

DoS and DDoS incidents ASD responded to rose more than 280% in FY2024–25 and were almost twice as common against critical infrastructure. That is why denial-of-service is not a default test type. Optus (2022) remains the Australian API and access-control case; Medibank (2022) remains the MFA-on-VPN case. Both are now in court or regulatory process. A penetration test asks whether a path is reachable, under written authorization, (ISC)²’s word, and signed rules of engagement. Black-box and assumed-breach are test designs, not marketing labels.

Security audits and assurance

The Essential Eight is still the live, supported baseline (November 2023). ASD consulted in mid-2026 on an Essentials series for enterprise IT, OT and cloud; that chapter is not yet the in-force document. An Essential Eight maturity level is not ISM completeness, and IRAP assesses a system, not a brand. In (ISC)² terms this is audit, governance and compliance, evidence mapped to a stated framework, at a date, with a boundary. We will never write “IRAP certified” about the company.

Ransomware response and recovery

Medibank’s public decision not to pay, and the later publication of health claims data, is why ASD’s ransomware advice and the Australian Government position exist. Preserve IOCs and precursor activity; do not reimage first; report via ReportCyber or 1300 CYBER1. (ISC)² splits the aftermath into incident response, business continuity and disaster recovery. None of those is a decryption guarantee, and maximum allowable downtime is a number your board sets, not a promise we print.

What this does not mean

Public cases are not our case studies. We do not imply we were engaged on Optus, Medibank, Latitude, Ivanti or MOVEit. We use the public record, ASD’s own statistics and (ISC)²’s defined terms so a buyer can see which of six services answers the year they are actually in.

Sources

Accountability

Published by Cybersecurity Engineering Pty Ltd, trading as MalwareAnalysis.app. This is general guidance, not advice about your incident. A named expert profile will be attached once approved for publication. Review this page again after 5 March 2027, or sooner if official ASD or OAIC guidance changes.

Related: all six services · first-hour ransomware · private vs public analysis.

Use the evidence in context

This article reflects understanding at its stated publication and review dates. It is general information, not advice about your specific incident, system or legal position.