Activity timeline
Storm-1175 appears in 3 tracked threats between and ; the busiest month was 2026-04 with 2 reports.
ATT&CK techniques observed
- T1021 Remote Services — Lateral Movementobserved in 3 of 3 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 3 of 3 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 3 of 3 tracked threats
- T1078 Valid Accounts — Privilege Escalationobserved in 3 of 3 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1136 Create Account — Persistenceobserved in 3 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1219 Remote Access Tools — Command and Controlobserved in 3 of 3 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 3 of 3 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 3 of 3 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 2 of 3 tracked threats
- T1018 Remote System Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1069 Permission Groups Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
Tracked threats
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin TakeoverCRITICAL
- ConnectWise ScreenConnect Path Traversal (CVE-2024-1708) Added to CISA KEV — Storm-1175 / Medusa Ransomware Active ExploitationHIGH
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)CRITICAL