logo

Storm-1175 Deploys Medusa Ransomware Within 24 Hours of Flaw Disclosure

ID: 179da6a0-7ffb-55fd-b4a9-57ad29b124d0

STIX ID: report--179da6a0-7ffb-55fd-b4a9-57ad29b124d0

Feed Name: HackRead

Threat Score
82/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Storm-1175 (associated with Medusa ransomware) is conducting highly time-sensitive campaigns that weaponize publicly disclosed and zero-day vulnerabilities to rapidly gain access, exfiltrate data, disable defenses (e.g., adding C:\ to AV exclusions), and deploy ransomware across multiple sectors and countries; researchers observed same-day exploitation of CVE-2025-31324 and pre-disclosure exploitation of CVE-2026-23760, with the group leveraging legitimate remote-management tools and deployment utilities to accelerate lateral movement and impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.