logo

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations

ID: fc93cf33-44c5-52ad-95b6-e551ad1a8052

STIX ID: report--fc93cf33-44c5-52ad-95b6-e551ad1a8052

Feed Name: Microsoft Security

Threat Score
82/100

Date Published: 2026-04-06

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes Storm-1175, a financially motivated ransomware actor that quickly weaponizes N‑day and zero‑day vulnerabilities in web‑facing systems to gain access, establish covert persistence, steal credentials, exfiltrate data (using tools like Rclone), and deploy Medusa ransomware; the report details observed TTPs, affected sectors and geographies, mitigation recommendations, and provides indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.