DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-28 10:00 UTC
incidenthighcontained

National Electricity Market (NEM) Grid Ingress Triage

EXECUTIVE INTELLIGENCE SUMMARY

Discovery of persistent living-off-the-land footholds in regional Australian transmission substation relays.

The Australian Cyber Security Centre (ACSC) and energy grid operators uncovered stealthy webshells and compromised SOHO proxy chains inside secondary substations across New South Wales and Queensland. The attackers refrained from disruptive actions, maintaining long-term dormant reconnaissance.

PHASED INCIDENT CHRONOLOGY
PHASE: Discovery2026-08-12 04:00 UTC
Anomalous SSH Tunneling from Domestic Router IP

Grid security sensor detects internal administrative login from consumer broadband IP block.

VERIFIED PROVENANCE TRAIL1 INDEPENDENT ATTESTATIONS
Persistence achieved via living-off-the-land binaries (LotLBs).
government2026-08-1498% CONFIDENCE
Australian Signals Directorate (ASD) / ACSC

Validated absence of custom malware binaries; reliance on built-in PowerShell and netsh commands.

SOURCE CITATIONS & ATTESTATIONS (1)
ASD / ACSC Energy Sector Threat BriefingAustralian Signals Directorate

Critical Infrastructure Pre-positioning Analysis

TELEMETRY CARDID: inc-2026-0740
ENTITY TYPE
incident
COORDINATES
-33.8688, 151.2093 (Australia)
INDEXED TAGS
#energy#power_grid#volt_typhoon#pre_positioning#scada#australia