logo

Microsoft Warns Storm-1175 Exploits Web-Facing Assets 0-Day Flaws in Medusa Ransomware Attacks

ID: b2c9b7df-0958-59b2-87e4-498986f989dc

STIX ID: report--b2c9b7df-0958-59b2-87e4-498986f989dc

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-07

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Storm-1175, a financially motivated threat actor, is conducting fast-moving ransomware campaigns that deploy Medusa ransomware after exploiting internet-facing systems via N-day and zero-day vulnerabilities; the group performs rapid lateral movement and data exfiltration (double extortion) using web shells, RMM tools, registry tampering, credential theft, and tools like Bandizip, Rclone, and PDQ Deployer, and defenders are urged to patch quickly, monitor for credential-theft and unauthorized registry changes, restrict RMM tools, and enforce MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.