Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

Storm-1175 public-facing intrusion wave

Updated 07.04.2026 09:35
Case score 56
Members 1 First seen 07.04.2026 09:35 Latest activity 07.04.2026 09:35

Overview

**Storm-1175** is running a high-velocity intrusion campaign that uses **zero-day** and **N-day** vulnerabilities to break into exposed internet-facing systems. Available evidence ties the activity to fast follow-on actions that include data theft and **Medusa ransomware**, sometimes within 24 hours. The activity spans multiple sectors and countries and has touched products such as **Exchange Server**, **Ivanti Connect Secure and Policy Secure**, **ConnectWise ScreenConnect**, **JetBrains TeamCity**, **SimpleHelp**, **GoAnywhere MFT**, **SmarterMail**, and **BeyondTrust**. Current defensive priority is rapid patching of exposed systems plus hunting for web shells, RMM abuse, credential theft, and exfiltration artifacts.
Latest development

Storm-1175 expands a multi-vulnerability Medusa campaign

Storm-1175, a China-based threat actor associated with Medusa ransomware, has been linked since 2023 to exploitation of more than 16 vulnerabilities across Microsoft Exchange Server, Papercut, Ivanti Connect Secure and Policy Secure, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, Fortra GoAnywhere MFT, SmarterTools SmarterMail, and BeyondTrust. The group uses zero-day and N-day vulnerabilities to gain initial access to internet-facing systems, including CVE-2025-10035 and CVE-2026-23760 as zero-days before public disclosure, and has also targeted Linux systems and vulnerable Oracle WebLogic instances in late 2024. After foothold acquisition, the operators use PowerShell, PsExec, Impacket, PDQ Deployer, Mimikatz, Rclone, web shells, and legitimate RMM software to move laterally, steal credentials, exfiltrate data, and deploy Medusa ransomware.

Signals

CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

1 listed

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Campaign Storm-1175 high-velocity zero-day and N-day intrusion campaign
Updated 07.04.2026 09:35 Lead Contribution 56
Objective Financial Extortion Campaign Active Patch Patch Available

**Storm-1175** is running a **high-velocity intrusion campaign** that chains **zero-day** and **N-day vulnerabilities** to gain initial access to exposed systems, raising the risk of rapid compromise and ransomware deployment. The activity is hitting **healthcare**, **education**, **professional services**, and **finance** organizations across **Australia**, the **United Kingdom**, and the **United States**. Once inside, the operators can exfiltrate data and deploy **Medusa ransomware** within **days** or even **24 hours**.