MalwareCritical

China-Linked Storm-1175 Deploys Medusa Ransomware via Zero-Day Exploit Chains

Wednesday, April 8, 2026
Australia, United Kingdom, United States
The Hacker News + Microsoft Threat Intelligence

Summary

China-linked threat actor Storm-1175 is conducting high-velocity ransomware attacks by chaining zero-day and N-day vulnerabilities to deploy Medusa ransomware against healthcare, education, professional services, and finance sectors. The group can complete full data exfiltration and ransomware deployment within 24 hours of initial access. Targets span Australia, the United Kingdom, and the United States.

Threat Analysis

Storm-1175 is a financially motivated cybercriminal group with ties to China, tracked by Microsoft Threat Intelligence for conducting 'high-velocity' attacks since 2023. The group exploits internet-facing systems using a combination of zero-day and recently disclosed N-day vulnerabilities, sometimes chaining multiple exploits for post-compromise activities. Since 2023, Storm-1175 has been linked to exploitation of over 16 vulnerabilities including CVE-2025-10035 (Fortra GoAnywhere MFT), CVE-2026-23760 (SmarterTools SmarterMail), and CVE-2026-1731 (BeyondTrust). Notably, CVE-2025-10035 and CVE-2026-23760 were exploited as zero-days before public disclosure. Post-compromise tactics include use of LOLBins (PowerShell, PsExec, Impacket), PDQ Deployer for lateral movement, Windows Firewall modification to enable RDP, credential dumping via Mimikatz, and data exfiltration via Rclone. The group also uses legitimate RMM tools (AnyDesk, Atera, MeshAgent, ConnectWise ScreenConnect) to camouflage malicious traffic. Mitigations: Apply patches for all internet-facing systems immediately, especially file transfer and remote access solutions. Implement behavioral monitoring for LOLBin abuse. Restrict use of RMM tools to approved vendors only. Maintain offline backups and test restoration procedures.

Last updated: Apr 8, 2026, 08:18 AM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM