Microsoft Warns Storm-1175 Exploiting Web-Facing Vulnerabilities to Deploy Medusa Ransomware
ID: 944e4a11-da3c-5754-a9bc-618348bac915
STIX ID: report--944e4a11-da3c-5754-a9bc-618348bac915
Feed Name: GBHackers
Microsoft warns that Storm‑1175 is rapidly exploiting internet‑facing N‑day (and occasionally zero‑day) vulnerabilities across numerous products to deliver Medusa ransomware, completing initial access to data theft and encryption in days or sometimes under 24 hours. The report identifies affected sectors (healthcare, education, professional services, financial), lists abused CVEs/products and post‑compromise techniques (web shells, RMM tool abuse, PDQ Deployer, Mimikatz, Rclone exfiltration, Defender tampering), and urges patching, hardening of internet‑facing services, RMM control, MFA, and Defender protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
