Storm-1175's Rapid Exploits Extend Beyond Initial Web Breach

Storm-1175, affiliated with Medusa ransomware, operates at a high tempo by exploiting recently disclosed and zero-day vulnerabilities against web-facing assets. They move from initial access to data exfiltration and ransomware deployment in as little as 24 hours. This rapid progression includes creating new user accounts and deploying legitimate remote monitoring and management (RMM) tools to maintain persistence. Consequently, patching alone does not remove their footholds. The threat actor's activity impacts healthcare, education, finance, and professional services sectors across multiple countries. Their use of legitimate admin tools and credential theft expands the blast radius beyond the initially exploited host to identity systems, backup systems, and endpoints accessible via RMM. This escalation in speed and technique demands detection and containment efforts that address post-exploitation artifacts, not just vulnerability patching.

Part of the PlainSec briefing for 2026-04-07

Sources