Storm-1175's Rapid Exploits Extend Beyond Initial Web Breach
Storm-1175, affiliated with Medusa ransomware, operates at a high tempo by exploiting recently disclosed and zero-day vulnerabilities against web-facing assets. They move from initial access to data exfiltration and ransomware deployment in as little as 24 hours. This rapid progression includes creating new user accounts and deploying legitimate remote monitoring and management (RMM) tools to maintain persistence. Consequently, patching alone does not remove their footholds. The threat actor's activity impacts healthcare, education, finance, and professional services sectors across multiple countries. Their use of legitimate admin tools and credential theft expands the blast radius beyond the initially exploited host to identity systems, backup systems, and endpoints accessible via RMM. This escalation in speed and technique demands detection and containment efforts that address post-exploitation artifacts, not just vulnerability patching.
CVSS 10 CRITICAL: a deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Oct 20 · date passed
Microsoft said it has been alarmed to see how effective Medusa actors are, citing multiple cases where the group can move from initial access to data exfiltration and ransomware deployment within 24 hours.
Microsoft says that Storm-1175, a China-based financially motivated cybercriminal group known for deploying Medusa ransomware payloads, has been deploying n-day and zero-day exploits in high-velocity attacks.