logo

Microsoft links Medusa ransomware affiliate to zero-day attacks

ID: bf1c073e-459a-5c87-bba9-5ddc01709e9d

STIX ID: report--bf1c073e-459a-5c87-bba9-5ddc01709e9d

Feed Name: DataBreaches.Net

Threat Score
80/100

Date Published: 2026-04-06

Date Updated: 2026-04-19

Author: Dissent

...
...

Microsoft warns that Storm-1175, a China-based financially motivated cybercriminal group, is rapidly exploiting n-day and zero-day vulnerabilities to gain access and deploy Medusa ransomware, often weaponizing flaws within a day and sometimes before patches are released; the group moves from initial access to data exfiltration and ransomware deployment within days and in some cases within 24 hours.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.