China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
ID: 1753ba1c-14b9-5caa-a9bb-b50644285bbc
STIX ID: report--1753ba1c-14b9-5caa-a9bb-b50644285bbc
Feed Name: The Hacker News
Executive summary: Microsoft Threat Intelligence links a China-based cybercriminal group known as Storm-1175 to high-velocity intrusions that chain zero-day and recently disclosed vulnerabilities to compromise internet-facing systems and rapidly exfiltrate data and deploy Medusa ransomware against healthcare, education, professional services, and finance organizations across Australia, the United Kingdom, and the United States; observed techniques include exploit chaining, RMM abuse, web shells, credential dumping (Mimikatz/Impacket), lateral movement (PsExec, PDQ Deployer), AV exclusion, and exfiltration via Bandizip and Rclone.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
