Storm-1175 Deploys Medusa Ransomware at 'High Velocity'
ID: 071e648f-308b-53a8-b254-2f7d27d07142
STIX ID: report--071e648f-308b-53a8-b254-2f7d27d07142
Feed Name: Dark Reading
Microsoft Threat Intelligence reports that Storm-1175 is conducting fast-paced ransomware campaigns delivering Medusa by rapidly exploiting known N-day and newly observed zero-day vulnerabilities (including multiple critical CVEs). Attacks move from exploitation to data exfiltration and ransomware deployment in days or hours, have targeted healthcare, education, professional services and finance across Australia, the UK and the US, and include tactics such as security-solution tampering (Microsoft Defender), credential theft and use of RMM/Impacket/Rclone; Microsoft recommends immediate patching, enabling Defender tamper protection and isolating internet-facing systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
