HomeSecurityStorm-1175: Zero-day exploit for Medusa ransomware deployment

Storm-1175: Zero-day exploit for Medusa ransomware deployment

The Chinese group Storm-1175 has been linked to exploiting zero-day vulnerabilities to rapidly deploy the Medusa ransomware to healthcare, education, and financial services organizations. According to Microsoft Threat Intelligence, the hacking group has proven to be extremely effective at identifying vulnerable systems and rapidly executing attacks. Its ability to exploit vulnerabilities before they are even widely known makes it one of the most dangerous threats in today’s cybersecurity landscape.

Storm-1175

Storm-1175 ’s attacks are characterized by the exploitation of zero-day exploits , in some cases even before their public disclosure. The group combines newly disclosed vulnerabilities to gain initial access to target systems . In select incidents, attackers chain together multiple exploits for malicious activity after the system is compromised. This “exploit chaining” tactic demonstrates the group’s deep technical expertise and ability to quickly adapt to new security environments.

See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit

Once gained access, the cybercriminal team moves quickly to extract data and deploy the Medusa ransomware within a few days, or even within 24 hours. Speed ​​of execution is a key characteristic of Storm-1175, making it extremely dangerous for organizations in Australia, the United Kingdom , and the United States. This high operational tempo creates minimal time for security teams to detect and respond to the threat, making prevention critical.

Storm-1175 Techniques and Tools

To facilitate its attacks, the group establishes persistent access by creating new user accounts, deploying web shells, or legitimate remote monitoring and management (RMM) software for lateral movement. In addition, it conducts credential theft and interferes with the normal operation of security solutions before deploying the ransomware. The use of legitimate RMM is a particularly insidious tactic, as these tools are often considered trustworthy by security systems and do not trigger alerts.

Storm-1175: Zero-day exploit for Medusa ransomware deployment

As of 2023, Storm-1175 has been linked to the exploitation of more than 16 vulnerabilities:

The variety of targeted products demonstrates the team's systematic approach to searching for vulnerabilities in widely used corporate systems.

Particularly concerning is that vulnerabilities CVE-2025-10035 and CVE-2026-23760 were exploited as zero-days before their public disclosure.

Since late 2024, the hacking group has shown a preference for targeting Linux, including exploiting vulnerable Oracle WebLogic in various organizations. This shift towards Linux reflects the growing adoption of these systems in enterprise environments and the need for enhanced security across all platforms.

See also: Medusa Ransomware demands $4 million ransom from NASCAR

Attack Tactics and Tools

Storm -1175 rapidly switches exploits between discovery and patch availability or adoption, taking advantage of the period when many organizations remain unprotected. This “window of opportunity” can last from a few days to weeks, depending on the complexity of the patch and the speed of organizations’ response.

Notable tactics observed in these attacks include advanced techniques for evading detection and exploiting legitimate system tools.

Attackers use living-off-the-land binaries (LOLBins), including PowerShell and PsExec, along with Impacket for lateral movement. They also rely on PDQ Deployer for both lateral movement and payload delivery (including Medusa ransomware). Another common tactic is modifying Windows Firewall to enable Remote Desktop Protocol (RDP) and deliver malicious payloads to other devices.

Additionally, they perform credential dumping using Impacket and Mimikatz, set up exceptions in Microsoft Defender Antivirus to prevent ransomware payloads from being blocked, and leverage Bandizip and Rclone for data collection and extraction. The use of Rclone is particularly concerning as it allows for bulk data transfer to cloud services, making the extraction difficult to detect and prevent.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Storm-1175: Zero-day exploit for Medusa ransomware deployment

Protection and Treatment Recommendations

To effectively protect against Storm-1175 attacks , organizations must adopt a multi-layered security approach. First, promptly applying all available security patches is critical, especially for systems exposed to the internet. Second, monitoring for suspicious RMM activity and implementing strict policies on the use of such tools can significantly limit attackers' capabilities.

See also: TrueConf: Zero-day vulnerability used in attacks on government networks

Additionally, organizations should enhance network segmentation to limit lateral movement, implement advanced detection and response (EDR) systems, and conduct regular attack simulation exercises. Training staff on the latest attack techniques and creating incident response plans are also crucial to minimizing the impact of a potential attack.

According to The Hacker News, the biggest implication here is that RMM tools like AnyDesk , Atera , MeshAgent , ConnectWise ScreenConnect , or SimpleHelp are becoming dual-use infrastructure for covert operations, as they allow threat actors to mix malicious traffic into trusted, encrypted platforms. This trend highlights the need for more sophisticated detection methods that can distinguish legitimate from malicious use of these tools.

Storm-1175 activity represents a significant evolution in the cyberthreat landscape, where attackers are combining advanced techniques with speed of execution for maximum impact. Organizations must adapt their security strategies to address these evolving threats, prioritizing prevention, rapid detection, and effective incident response.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS