MalwareCritical

China-Linked Storm-1175 Deploys Medusa Ransomware in High-Velocity Attacks

Tuesday, April 7, 2026
Australia, United Kingdom, United States
The Hacker News + BleepingComputer

Summary

China-based threat actor Storm-1175 is conducting high-velocity ransomware campaigns deploying Medusa ransomware against healthcare, education, professional services, and finance sectors in Australia, UK, and US. The group chains zero-day and N-day vulnerabilities for rapid compromise and post-exploitation activities.

Threat Analysis

Storm-1175, a China-based advanced persistent threat (APT) actor tracked by Microsoft Threat Intelligence, is conducting high-velocity attacks leveraging a combination of zero-day and N-day vulnerabilities to deploy Medusa ransomware. The group has heavily impacted healthcare organizations, as well as those in education, professional services, and finance sectors across Australia, the United Kingdom, and the United States. Storm-1175 has been observed exploiting vulnerabilities before public disclosure and chaining multiple exploits for post-compromise activities including lateral movement, data exfiltration, and ransomware deployment. The group's use of zero-day exploits combined with rapid weaponization of newly disclosed vulnerabilities makes traditional patch management insufficient as a sole defense. Recommended mitigations: Implement network segmentation to limit lateral movement, deploy endpoint detection and response (EDR) solutions, maintain offline backups, apply patches immediately upon release, and monitor for indicators of compromise associated with Medusa ransomware.

Last updated: Apr 7, 2026, 08:18 AM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM