Storm-1175 is a China-based, financially motivated threat actor tracked by Microsoft Threat Intelligence. It has operated as a prominent Medusa ransomware affiliate and began deploying the distinct C++ ransomware family StormEncryptor on August 2, 2026. Its targets include healthcare providers, financial institutions, education organizations, and professional services firms in the United States, United Kingdom, and Australia. The actor conducts high-velocity intrusions, sometimes progressing from initial access to ransomware encryption in less than 24 hours. Storm-1175 obtains initial access primarily by exploiting vulnerabilities in internet-facing applications and remote management systems. Since 2023, its exploitation activity has affected products including Microsoft Exchange, PaperCut, Ivanti Connect Secure, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, GoAnywhere MFT, SmarterMail, and BeyondTrust. Confirmed techniques include exploitation of GoAnywhere MFT vulnerability CVE-2025-10035, the ScreenConnect vulnerability chain CVE-2024-1709 and CVE-2024-1708, and VMware ESXi vulnerability CVE-2024-37085 to obtain administrative access to domain-joined hypervisors. Post-compromise operations combine hands-on-keyboard activity with legitimate administration tools. Storm-1175 uses AnyDesk and SimpleHelp for remote access and persistence, Advanced IP Scanner for network discovery, and Mimikatz for LSASS credential dumping. Its operations also employ PowerShell, PsExec, RDP, WMI, and Impacket to expand access and support ransomware deployment. Abuse of compromised remote monitoring and management infrastructure enables access to downstream customer environments. The actor rapidly exfiltrates data and deploys ransomware, combining encryption with threats to publish stolen information. StormEncryptor ransom demands give victims three days to contact the attackers and negotiate payment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
23 CVEs this actor has used in observed campaigns. 23 of them exploited in the wild.
Microsoft says that Storm-1175 most likely used a publicly known zero-day vulnerability, CVE-2026-18577, to gain unauthorized access to N-central. N-able identified active exploitation on July 31; its first patch was ineffective, and it later issued two additional emergency patches. The vulnerability has a CVSS score of 8.2 and was added to CISA's Known Exploited Vulnerabilities catalog on August 3.
Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2023-21529 (Microsoft Exchange)
A critical deserialization vulnerability in GoAnywhere MFT’s License Servlet (CVSS 10.0) is actively being exploited in the wild. The flaw allows attackers with a forged license response signature to deserialize arbitrary objects, which can lead to command injection and remote code execution (RCE).
Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2024-1709 and CVE-2024-1708 (ConnectWise ScreenConnect)
Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2023-27351 and CVE-2023-27350 (Papercut)
18 more CVEs tied to this actor tracked in Mallory.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-based financially motivated actor formerly affiliated with Medusa; it exploits recently disclosed vulnerabilities, uses credential phishing, and has begun deploying StormEncryptor instead of Medusa.
A financially motivated, China-based ransomware group that exploits N-central remote-monitoring-and-management infrastructure to compromise managed organizations. It previously conducted Medusa ransomware activity and has shifted to StormEncryptor, accelerating ransom operations against downstream victims within 24 hours.
A group identified by Microsoft as using Medusa ransomware in fast-paced operations.
A financially motivated ransomware actor conducting rapid attacks by exploiting newly disclosed and sometimes zero-day vulnerabilities in exposed systems, then moving quickly to data theft and ransomware deployment. The group has shifted from using Medusa to a new ransomware called StormEncryptor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.