Threadlinqs IntelligenceStart free

Threat actorCNTracked since 2026-04

Storm-1175

As of 2026-09-14, Storm-1175 is a CN-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning vulnerability, ransomware. ATT&CK coverage spans 52 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1021 (Remote Services), T1059 (Command and Scripting Interpreter), T1071 (Application Layer Protocol).

Tracked threats
32 critical · 1 high
First seen
2026-04-06
Last seen
2026-08-03
ATT&CK techniques
52across 3 of 3 threats
Related CVEs
20Referenced by its activity
Attribution
CNNation or origin
Nation: CN · 3 tracked threat(s) · Categories: VULNERABILITY, RANSOMWARE

Activity timeline

Storm-1175 appears in 3 tracked threats between and ; the busiest month was 2026-04 with 2 reports.

ATT&CK techniques observed

52 techniques observed across 3 of 3 tracked threats · Discovery (11), Stealth (formerly Defense Evasion) (7), Command and Control (6), Execution (5), Persistence (5), Initial Access (4)
  • T1021 Remote Services — Lateral Movementobserved in 3 of 3 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 3 of 3 tracked threats
  • T1078 Valid Accounts — Privilege Escalationobserved in 3 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1136 Create Account — Persistenceobserved in 3 of 3 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 3 of 3 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 3 of 3 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 3 of 3 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 2 of 3 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1069 Permission Groups Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats

Tracked threats

Related CVEs

20 CVEs referenced by tracked Storm-1175 activity