logo

Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks

ID: 35dc8717-9d73-5e45-87f1-7e4523ab8e33

STIX ID: report--35dc8717-9d73-5e45-87f1-7e4523ab8e33

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

...
...

**Executive summary:** Microsoft attributes a high-tempo Medusa ransomware campaign to Storm-1175, a financially motivated actor exploiting at least 16 vulnerabilities (including zero-days) to rapidly gain access and deploy ransomware across healthcare, education, professional services, and finance in Australia, the UK and the US; the report outlines the group's TTPs (web shells, new admin accounts, LOLBins, RMM tools, Cloudflare tunnels, PDQ Deployer, Impacket) and recommends perimeter hardening, credential hygiene, MFA, tamper protection, and XDR tuning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.