RansomwareApr 6, 2026
Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations
Storm-1175 exploits recently disclosed vulnerabilities to deploy Medusa ransomware in high-velocity campaigns.
Summary
Storm-1175, a financially motivated threat actor, is conducting rapid ransomware campaigns that leverage recently disclosed vulnerabilities to compromise web-facing assets, exfiltrate data, and deploy Medusa ransomware (tracked as Gaze.exe). The actor targets vulnerable internet-exposed systems for initial access and executes high-tempo operations across multiple victims.
Indicators of Compromise
- malware — Medusa
- malware — Gaze.exe
Entities
Storm-1175 (threat_actor)Microsoft (vendor)