Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Storm-1175 focuses gaze on vulnerable web-facing assets in high ...

9f829f7343d5d5da7c397fa6efda4a4e

TLP:CLEAR
Active

MD5 Hash

Description

The financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 operates high-velocity ransomware campaigns that weaponize N-days, targeting vulnerable, web-facing systems during the window between vulnerability disclosure and widespread patch adoption. Following successful exploitation, Storm-1175 rapidly moves from initial access to data exfiltration and deployment of Medusa ransomware, often within a few days and, in some cases, within 24 hours. The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have proven successful, with recent intrusions heavily impacting healthcare organizations, as well as those in the education, professional services, and finance sectors in Australia, United Kingdom, and United States.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Storm-1175 focuses gaze on vulnerable web-facing assets in high ...
Pattern Type
STIX
Confidence
75%
Valid From
May 6, 2026 04:49
Total Sightings
0
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 9f829f7343d5d5da7c397fa6efda4a4e

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.