Tag: Medusa Ransomware

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
News

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware

The weaponization of a mix of zero-day and N-day vulnerabilities to plan "high-velocity" attacks and breach vulnerable internet-facing systems has been connected to a threat actor based in China that is well-known for using Medusa ransomware. According to the Microsoft Threat Intelligence team, recent intrusions have had a significant impact on healthcare organizations as well as those in the education, professional services, and finance sectors in Australia, the United Kingdom, and the United States due to the threat actor's high operational tempo and skill in identifying exposed perimeter assets. In order to get initial access, Storm-1175's attacks have also made use of freshly discovered vulnerabilities and, in certain situations, zero-day exploits that have not yet been made pub...
Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware
News

Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware

Microsoft said Monday that a threat actor it monitors as Storm-1175 exploited a serious security hole in Fortra GoAnywhere software to make it easier for the Medusa ransomware to spread. The major deserialization flaw, CVE-2025-10035 (CVSS score: 10.0), has the potential to allow command injection without authentication. The Sustain Release 7.6.3, or version 7.8.4, addressed it. According to the Microsoft Threat Intelligence team, the vulnerability can enable a threat actor to deserialize an arbitrary actor-controlled object using a legitimately faked license response signature, potentially resulting in command injection and remote code execution (RCE). The tech firm claims that since September 11, 2025, the cybercriminal gang Storm-1175 has been using Medusa ransomware and gaini...
Medusa Ransomware Hackers Claim Attack on Cyprus University
News

Medusa Ransomware Hackers Claim Attack on Cyprus University

The Open University of Cyprus (OUC) was the target of a cyberattack that disrupted operations. The Medusa ransomware organisation has taken responsibility and is now demanding $100,000 to remove the data or it will be made public online. OUC is an online university with a location in Nicosia, Cyprus. It engages in a variety of scientific research projects and provides remote learning to 4,200 students through 30 higher education programmes. On March 27, a number of major services and crucial systems were attacked. As a result, access to a number of learning portals and other services was constrained. OUC has 14 days to react to the hackers' ransom demands after they exposed OUC data on their leak site read more Medusa Ransonware Hackers Claim Attack on Cyprus University. With ReconB...