Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations
ID: fc93cf33-44c5-52ad-95b6-e551ad1a8052
STIX ID: report--fc93cf33-44c5-52ad-95b6-e551ad1a8052
Feed Name: Microsoft Security
Threat Score
Microsoft Threat Intelligence describes Storm-1175, a financially motivated ransomware actor that quickly weaponizes N‑day and zero‑day vulnerabilities in web‑facing systems to gain access, establish covert persistence, steal credentials, exfiltrate data (using tools like Rclone), and deploy Medusa ransomware; the report details observed TTPs, affected sectors and geographies, mitigation recommendations, and provides indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
