← Back to BrewedIntel
malwarehighExploitationFinancially Motivated CybercrimeRansomwareMedusa RansomwareStorm-1175

Apr 07, 2026 • Rob Wright

Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

Microsoft has identified Storm-1175, a financially motivated cybercrime group, deploying Medusa Ransomware in high-velocity campaigns. The threat actor...

Source
Dark Reading
Category
malware
Severity
high

Executive Summary

Microsoft has identified Storm-1175, a financially motivated cybercrime group, deploying Medusa Ransomware in high-velocity campaigns. The threat actor exploits both N-day and zero-day vulnerabilities to gain initial access and execute attacks rapidly. Medusa ransomware encrypts victim data, demanding payment for decryption keys. Organizations should prioritize patch management to address known vulnerabilities, implement network segmentation, maintain offline backups, and deploy endpoint detection and response solutions to mitigate this ransomware threat.

Summary

Microsoft says the financially motivated cybercrime group has exploited N-day and zero-day vulnerabilities in campaigns predicated on speed.

Published Analysis

Microsoft has identified Storm-1175, a financially motivated cybercrime group, deploying Medusa Ransomware in high-velocity campaigns. The threat actor exploits both N-day and zero-day vulnerabilities to gain initial access and execute attacks rapidly. Medusa ransomware encrypts victim data, demanding payment for decryption keys. Organizations should prioritize patch management to address known vulnerabilities, implement network segmentation, maintain offline backups, and deploy endpoint detection and response solutions to mitigate this ransomware threat. Microsoft says the financially motivated cybercrime group has exploited N-day and zero-day vulnerabilities in campaigns predicated on speed. Microsoft says the financially motivated cybercrime group has exploited N-day and zero-day vulnerabilities in campaigns predicated on speed.

Linked Entities

  • Medusa Ransomware
  • Storm-1175