Fast-moving Storm-1175 uses new exploits to breach networks and drop Medusa
ID: bbd21b34-7f94-5aea-a92a-abe7033e5031
STIX ID: report--bbd21b34-7f94-5aea-a92a-abe7033e5031
Feed Name: Security Affairs
Storm-1175 is a China-based, financially motivated group that rapidly weaponizes newly disclosed (and in some cases zero-day) vulnerabilities in internet-facing systems to gain access, chain exploits, deploy web shells and remote tools, steal credentials, move laterally, exfiltrate data, and deploy Medusa ransomware — often completing attacks within 24 hours against targets in healthcare, education, finance and services across the US, UK and Australia; Microsoft provided IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
