Microsoft Warns Storm-1175 Exploits Web-Facing Assets 0-Day Flaws in Medusa Ransomware Attacks
ID: b2c9b7df-0958-59b2-87e4-498986f989dc
STIX ID: report--b2c9b7df-0958-59b2-87e4-498986f989dc
Feed Name: cybersecurityNews.com
Storm-1175, a financially motivated threat actor, is conducting fast-moving ransomware campaigns that deploy Medusa ransomware after exploiting internet-facing systems via N-day and zero-day vulnerabilities; the group performs rapid lateral movement and data exfiltration (double extortion) using web shells, RMM tools, registry tampering, credential theft, and tools like Bandizip, Rclone, and PDQ Deployer, and defenders are urged to patch quickly, monitor for credential-theft and unauthorized registry changes, restrict RMM tools, and enforce MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
