Back to Feed
RansomwareApr 6, 2026

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations

Storm-1175 exploits recently disclosed vulnerabilities to deploy Medusa ransomware in high-velocity campaigns.

Summary

Storm-1175, a financially motivated threat actor, is conducting rapid ransomware campaigns that leverage recently disclosed vulnerabilities to compromise web-facing assets, exfiltrate data, and deploy Medusa ransomware (tracked as Gaze.exe). The actor targets vulnerable internet-exposed systems for initial access and executes high-tempo operations across multiple victims.

Indicators of Compromise

  • malware — Medusa
  • malware — Gaze.exe

Entities

Storm-1175 (threat_actor)Microsoft (vendor)