INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Storm-1175 Deploys Medusa Ransomware at High Velocity

| 2026-04-07 20:15 CRITICAL HIGH
Executive Summary AI-generated
The threat actor's high operational tempo and proficiency in identifying exposed perimeter assets have proven successful, with recent intrusions heavily impacting healthcare organizations, as well as those in the education, professional services, and finance sectors. The most recent example is CVE-2026-23760, a critical authentication bypass vulnerability in SmarterMail that was exploited by various threat groups including China-linked Storm-2603. Related incidents include Iran's deployment of 'Pseudo-Ransomware' and its revival of Pay2Key operations, highlighting the group's ability to tamper with security solutions like Microsoft Defender Antivirus. The use of Medusa Ransomware at 'High Velocity', a financially motivated cybercrime group, has been observed in campaigns conducted by Storm-1175 actors who are running up-tempo campaigns to deliver ransomware, putting pressure on organizations to patch critical vulnerabilities faster.
Technical Mitigations AI-generated
* Implement a patching strategy that prioritizes immediate release of patches for critical vulnerabilities, as recommended by Microsoft Threat Intelligence. * Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses before they can be exploited by Storm-1175 or other threat actors. * Use secure coding practices and follow best security practices when developing software applications to prevent exploitation of known vulnerabilities. * Implement a robust incident response plan that includes procedures for responding to Medusa ransomware attacks, such as isolating affected systems and providing support to affected organizations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Pay2KeyPay2KeyMedusa RansomwareMedusa Ransomware CVE-2023-21529CVE-2023-21529 CVE-2025-31161CVE-2025-31161 CVE-2026-1731CVE-2026-1731 CVE-2026-23760CVE-2026-23760 CVE-2025-10035CVE-2025-10035 CVE-2024-27198CVE-2024-27198
Target & Sectors
FIVE_EYES FIVE_EYES NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎February 2023
Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations.
organisation CVE-2025-31161
organisation CVE-2024-27198
organisation CVE-2023-21529
organisation JetBrains
organisation Microsoft Exchange
infrastructure Smartermail
organisation GoAnywhere MFT
organisation SmarterMail
organisation MFT
organisation License Servlet
infrastructure Windows
organisation Windows' Credential Guard
organisation DMZ
‎March 2024
Storm-1175 deployed Medusa ransomware targeting Microsoft Exchange systems.
organisation CVE-2025-31161
organisation CVE-2024-27198
organisation CVE-2023-21529
organisation JetBrains
organisation Microsoft Exchange
‎2025/04/07
Storm-1175 deployed Medusa ransomware against GoAnywhere Managed File Transfer on April 7, 2025.
organisation GoAnywhere Managed File Transfer
‎Feb. 6
The vulnerability was initially disclosed on February 6 and quickly came under attack by the Medusa ransomware.
attribution the Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎April 6
Storm-1175 deployed Medusa ransomware on High Velocity systems.
organisation Storm-1175
‎2026/04/07
Storm-1175 Deploys Medusa Ransomware at 'High Velocity'.
infrastructure Smartermail
organisation SmarterMail
organisation MFT
infrastructure Ivanti
organisation Microsoft Defender Antivirus
organisation Exchange
organisation Papercut
organisation Ivanti Connect Secure and Policy Secure
organisation ConnectWise ScreenConnect
organisation JetBrains TeamCity
organisation SimpleHelp
organisation BeyondTrust
organisation Storm-1175
organisation Microsoft
organisation Implementing Credential Guard
organisation Removing
organisation MFA
organisation Configuring XDR
organisation PsExec
organisation Cloudflare
organisation RMM
organisation PDQ Deployer
organisation CVE-2026
organisation BeyondTrust Remote Support
organisation Privileged Remote Access
organisation CVE-2025-10035
organisation DMZ
Tactical Metrics
Metrics
infrastructure
‎Smartermail
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Ivanti
Affected Product
Intelligence Sources
Infosecurity-Magazine 2026-04-07