Back to Feed
RansomwareApr 6, 2026

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations

Storm-1175 exploits recently disclosed vulnerabilities to deploy Medusa ransomware in high-velocity campaigns.

Vendor Watch

Run Microsoft?

Get an email when a reviewed story names Microsoft, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Storm-1175, a financially motivated threat actor, is conducting rapid ransomware campaigns that leverage recently disclosed vulnerabilities to compromise web-facing assets, exfiltrate data, and deploy Medusa ransomware (tracked as Gaze.exe). The actor targets vulnerable internet-exposed systems for initial access and executes high-tempo operations across multiple victims.

Indicators of Compromise

  • malware — Medusa
  • malware — Gaze.exe

Entities

Storm-1175 (threat_actor)Microsoft (vendor)