logo

Microsoft Warns Storm-1175 Exploiting Web-Facing Vulnerabilities to Deploy Medusa Ransomware

ID: 944e4a11-da3c-5754-a9bc-618348bac915

STIX ID: report--944e4a11-da3c-5754-a9bc-618348bac915

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Microsoft warns that Storm‑1175 is rapidly exploiting internet‑facing N‑day (and occasionally zero‑day) vulnerabilities across numerous products to deliver Medusa ransomware, completing initial access to data theft and encryption in days or sometimes under 24 hours. The report identifies affected sectors (healthcare, education, professional services, financial), lists abused CVEs/products and post‑compromise techniques (web shells, RMM tool abuse, PDQ Deployer, Mimikatz, Rclone exfiltration, Defender tampering), and urges patching, hardening of internet‑facing services, RMM control, MFA, and Defender protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.