Storm-1175 public-facing intrusion wave
Case score 56
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 56
- Main story score
- 56
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Campaign Campaign record describes rapid exploitation of exposed systems, post-compromise tooling, and fast ransomware follow-on across multiple sectors and countries. main
Overview
Storm-1175 expands a multi-vulnerability Medusa campaign
Storm-1175, a China-based threat actor associated with Medusa ransomware, has been linked since 2023 to exploitation of more than 16 vulnerabilities across Microsoft Exchange Server, Papercut, Ivanti Connect Secure and Policy Secure, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, Fortra GoAnywhere MFT, SmarterTools SmarterMail, and BeyondTrust. The group uses zero-day and N-day vulnerabilities to gain initial access to internet-facing systems, including CVE-2025-10035 and CVE-2026-23760 as zero-days before public disclosure, and has also targeted Linux systems and vulnerable Oracle WebLogic instances in late 2024. After foothold acquisition, the operators use PowerShell, PsExec, Impacket, PDQ Deployer, Mimikatz, Rclone, web shells, and legitimate RMM software to move laterally, steal credentials, exfiltrate data, and deploy Medusa ransomware.