China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
The weaponization of a mix of zero-day and N-day vulnerabilities to plan "high-velocity" attacks and breach vulnerable internet-facing systems has been connected to a threat actor based in China that is well-known for using Medusa ransomware.
According to the Microsoft Threat Intelligence team, recent intrusions have had a significant impact on healthcare organizations as well as those in the education, professional services, and finance sectors in Australia, the United Kingdom, and the United States due to the threat actor's high operational tempo and skill in identifying exposed perimeter assets.
In order to get initial access, Storm-1175's attacks have also made use of freshly discovered vulnerabilities and, in certain situations, zero-day exploits that have not yet been made pub...



