Back to Feed
RansomwareApr 6, 2026

Microsoft links Medusa ransomware affiliate to zero-day attacks

Microsoft links Storm-1175 ransomware group to zero-day exploit attacks.

Vendor Watch

Run Microsoft?

Get an email when a reviewed story names Microsoft, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Microsoft has attributed Storm-1175, a China-based financially motivated cybercriminal group known for Medusa ransomware deployments, to conducting high-velocity attacks using zero-day and n-day exploits. The group is actively exploiting previously unknown vulnerabilities in addition to known vulnerabilities to compromise targets at scale. This represents a significant escalation in the group's capabilities and threat level.

Indicators of Compromise

  • malware — Medusa

Entities

Storm-1175 (threat_actor)Microsoft (vendor)