The 24-Hour Blitz: Storm-1175 Weaponizes Zero-Days for High-Velocity Ransomware
ID: 9c980296-c6ad-59d5-97e0-bee929b0221b
STIX ID: report--9c980296-c6ad-59d5-97e0-bee929b0221b
Feed Name: securityonline.info
**Storm-1175 (Microsoft Threat Intelligence)**: Microsoft describes Storm-1175 as a financially motivated, high-velocity threat actor that weaponizes N-day and zero-day vulnerabilities to move from initial breach to full Medusa ransomware deployment within 24–72 hours, using tools like Rclone for continuous exfiltration and PDQ Deployer or Group Policy for rapid mass encryption; the group targets web-facing assets across healthcare, education, and finance and employs a double-extortion model, with recommended mitigations including rapid patching, tamper protection, and monitoring of data sync utilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
