Microsoft said threat actor Storm-1175 is running high-tempo intrusions that exploit newly disclosed and, in some cases, previously unknown vulnerabilities in internet-facing systems to steal data and deploy Medusa ransomware within days or even 24 hours. The financially motivated group has heavily impacted healthcare organizations and also targeted education, professional services, and finance in Australia, the United Kingdom, and the United States. Since 2023, the actor has exploited more than 16 flaws across products including Microsoft Exchange, PaperCut, Ivanti, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, GoAnywhere MFT, SmarterMail, SAP NetWeaver, and BeyondTrust, with Microsoft also observing zero-day use against SmarterMail and GoAnywhere before public disclosure.
After gaining access, Storm-1175 establishes persistence with new administrator accounts, web shells, and remote management tools, then moves laterally using LOLBins, Impacket, PDQ Deployer, and Cloudflare tunnels while stealing credentials from LSASS, NTDS.dit, SAM, and backup systems. Microsoft said the actor tampers with Microsoft Defender settings to reduce detection, uses Bandizip and Rclone for collection and exfiltration, and deploys Medusa through PDQ Deployer or Group Policy; the group has also shown interest in Linux targets such as vulnerable Oracle WebLogic servers. Microsoft urged organizations to reduce exposure of web-facing assets, patch quickly, enforce MFA on approved RMM tools, restrict local administrator rights, and enable protections such as Credential Guard, tamper protection, and Defender XDR attack disruption features.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
CISA, the FBI, and HHS published an updated advisory on Medusa that said the ransomware-as-a-service group had adopted new initial-access tactics, including use of access brokers, and often exploited newly announced vulnerabilities in products such as Fortra GoAnywhere and BeyondTrust. The advisory said Medusa's known victim count had risen from more than 300 in March 2025 to more than 500 by April 2026.
Microsoft Threat Intelligence publicly profiled Storm-1175 as a financially motivated actor associated with Medusa ransomware and detailed its exploitation, persistence, credential theft, lateral movement, exfiltration, and defense-evasion techniques. The company also issued mitigation guidance focused on reducing exposure of web-facing assets and hardening defenses such as Credential Guard, tamper protection, MFA, and Defender XDR protections.
Across its campaigns, Storm-1175 significantly affected healthcare organizations and also targeted education, professional services, and finance entities in Australia, the United Kingdom, and the United States. Microsoft said the actor maintained a high operational tempo across these sectors.
Microsoft observed Storm-1175 exploiting zero-day vulnerabilities in SmarterMail and GoAnywhere MFT before those flaws were publicly disclosed. This showed the actor was not limited to patch-gap exploitation and could also leverage previously unknown vulnerabilities.
Since 2023, Microsoft observed Storm-1175 conducting high-tempo intrusions by rapidly weaponizing newly disclosed N-day vulnerabilities in web-facing products such as Exchange, PaperCut, Ivanti, ScreenConnect, TeamCity, SimpleHelp, CrushFTP, GoAnywhere MFT, SmarterMail, SAP NetWeaver, and BeyondTrust. The actor often moved from exploitation to credential theft, data exfiltration, and Medusa ransomware deployment within days or as little as 24 hours.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcehackread.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.