Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035) — Threadlinqs Intelligence
As of 2026-05-30, Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035) is a critical-severity ransomware threat attributed to Storm-1175 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0326 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: RANSOMWARE
Attribution: Storm-1175 · China · FINANCIAL
Microsoft Threat Intelligence linked Storm-1175, a China-based financially motivated threat group, to high-tempo Medusa ransomware operations exploiting zero-day vulnerabilities in SmarterMail
Storm-1175 is a China-based, financially motivated cybercriminal group tracked by Microsoft Threat Intelligence, operating as an affiliate within the Medusa ransomware-as-a-service (RaaS) ecosystem. The group is characterized by exceptionally high operational tempo and proficiency in identifying and exploiting vulnerable, internet-facing assets — often achieving full ransomware deployment within 24 hours of initial compromise.
## Primary Exploit Vectors
The campaign leverages two critical zero-day vulnerabilities as primary entry points:
**CVE-2026-23760 — SmarterMail Authentication Bypass (CVSS 9.8)**
An authentication bypass vulnerability in SmarterTools SmarterMail prior to build 9511. The `/api/v1/auth/force-reset-password` endpoint is marked `AllowAnonymous` and fails to verify the existing password or require a valid reset token when the `IsSysAdmin` parameter is set to `true`. An unauthenticated attacker can reset the system administrator password by sending a crafted POST request, achieving full admin account takeover. From the admin panel, the attacker can achieve SYSTEM-level remote code execution via System Event hooks (domain creation triggers) or Volume Mount command injection. PoC exploit code is publicly available and a Nuclei detection template exists. CISA added this CVE to the Known Exploited Vulnerabilities catalog with a remediation due date of February 16, 2026. In-the-wild exploitation was first observed on January 17, 2026 — just two days after the patch release — indicating attackers reverse-engineered the security fix via decompiler analysis.
**CVE-2025-10035 — GoAnywhere MFT Deserialization RCE (CVSS 10.0)**
A critical deserialization vulnerability in Fortra GoAnywhere MFT's License Servlet affecting versions prior to 7.6.3 and 7.7.0 through 7.8.3. The flaw permits an attacker with a forged license response signature to deserialize an arbitrary attacker-controlled object, leading to command injection and unauthenticated remote code execution. Exploitation was first detected on September 11, 2025, seven days before Fortra released a patch on September 18, 2025, confirming true zero-day status. CISA added this to the KEV catalog with a due date of October 20, 2025.
## Full Attack Chain
Storm-1175 follows a consistent, rapid operational playbook:
1. **Initial Access**: Exploit CVE-2026-23760 (SmarterMail auth bypass → admin RCE) or CVE-2025-10035 (GoAnywhere deserialization → RCE). The group has also historically exploited CVE-2023-21529 (Exchange), CVE-2023-27350/27351 (PaperCut), CVE-2023-46805/CVE-2024-21887 (Ivanti), CVE-2024-1709/1708 (ScreenConnect), CVE-2024-27198/27199 (TeamCity), CVE-2024-57726/57727/57728 (SimpleHelp), CVE-2025-31161 (CrushFTP), and CVE-2026-1731 (BeyondTrust).
2. **Persistence**: Deploy remote monitoring and management (RMM) tools including SimpleHelp and MeshAgent under the compromised application process. Create unauthorized local and domain administrator accounts. Plant .jsp web shells within MFT application directories for backup access.
3. **Defense Evasion**: Clear command history, use obfuscated/encrypted payloads, disable or modify endpoint security tools using KillAV and AbyssWorker (BYOVD — Bring Your Own Vulnerable Driver technique).
4. **Credential Access**: Dump LSASS memory using Mimikatz to harvest domain credentials.
5. **Discovery**: Execute network scanning with Netscan and Advanced IP Scanner to map the environment. Enumerate network shares, system configurations, domain groups, and user permissions.
6. **Lateral Movement**: Leverage stolen credentials with Remote Desktop Protocol (mstsc.exe), PsExec for remote command execution, and software deployment tools (PDQ Deploy, BigFix) to propagate across the network.
7. **Command and Control**: Establish C2 communications through deployed RMM tools and Cloudflare tunnels, providing encrypted and resilient command channels that blend with legitimate traffic.
8. **Exfiltration**: Deploy Rclone to exfi
Weaknesses (CWE)
CWE-288, CWE-502, CWE-77
Target sectors: healthcare, education, professional-services, finance, critical-infrastructure, technology, legal, insurance, manufacturing, government
Target regions: United States, United Kingdom, Australia
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2026-23760, CVE-2025-10035, CVE-2025-52691, CVE-2026-1731, CVE-2025-31161, CVE-2024-57726, CVE-2024-57727, CVE-2024-57728, CVE-2024-27198, CVE-2024-27199, T1190, T1566, T1059, T1059, T1047, T1136, T1505, T1078, T1070, T1027