[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftTMebnJNXRCUjcz1GkZjCRFCCQTNUpJ8EC5SHJZ1iNc":3},{"article":4,"iocs":43,"watch_terms":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":23,"category":24,"article_tags":27},"6aea547d-8c2d-4699-a60c-23e93f2f9ca7","Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations","storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ran","The financially motivated cybercriminal threat actor Storm-1175 operates high-velocity ransomware campaigns that weaponize recently disclosed vulnerabilities to obtain initial access, exfiltrate data, and deploy Medusa ransomware (Gaze.exe). The post Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations appeared first on Microsoft Security Blog.","Storm-1175, a financially motivated threat actor, is conducting rapid ransomware campaigns that leverage recently disclosed vulnerabilities to compromise web-facing assets, exfiltrate data, and deploy Medusa ransomware (tracked as Gaze.exe). The actor targets vulnerable internet-exposed systems for initial access and executes high-tempo operations across multiple victims.","Storm-1175 exploits recently disclosed vulnerabilities to deploy Medusa ransomware in high-velocity campaigns.",null,"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F04\u002F06\u002Fstorm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations\u002F","2026-04-06T16:00:00+00:00","2026-04-06T18:00:21.098461+00:00",8,[17,20],{"name":18,"type":19},"Storm-1175","threat_actor",{"name":21,"type":22},"Microsoft","vendor","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":23,"icon":11,"name":25,"slug":26},"Ransomware","ransomware",[28,33,38],{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":39},{"id":40,"icon":11,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[44,48],{"type":45,"value":46,"context":47},"malware","Medusa","Ransomware payload deployed by Storm-1175; also tracked as Gaze.exe",{"type":45,"value":49,"context":50},"Gaze.exe","Executable variant of Medusa ransomware deployed by Storm-1175",[21]]