RansomwareApr 6, 2026
Microsoft links Medusa ransomware affiliate to zero-day attacks
Microsoft links Storm-1175 ransomware group to zero-day exploit attacks.
Vendor Watch
Run Microsoft?
Get an email when a reviewed story names Microsoft, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Microsoft has attributed Storm-1175, a China-based financially motivated cybercriminal group known for Medusa ransomware deployments, to conducting high-velocity attacks using zero-day and n-day exploits. The group is actively exploiting previously unknown vulnerabilities in addition to known vulnerabilities to compromise targets at scale. This represents a significant escalation in the group's capabilities and threat level.
Indicators of Compromise
- malware — Medusa
Entities
Storm-1175 (threat_actor)Microsoft (vendor)