Microsoft Links Medusa Ransomware Affiliate to Zero-Day and N-Day Exploits in Rapid Attacks

What happened Microsoft said Storm-1175, a China-based financially motivated threat group known for deploying Medusa ransomware, has been using both zero-day and n-day vulnerabilities in high-velocity attacks. The company said the group ...

Response to CISA Advisory (AA25-071A): #StopRansomware: Medusa Ransomware

AttackIQ has released a new assessment template in response to the CISA Advisory (AA25-071A) published on March 12, 2025, which details new behaviors exhibited by Medusa Ransomware. The post Response to CISA ...

Emulating the Petrifying Medusa Ransomware

AttackIQ has released a new attack graph that emulates the behaviors exhibited by Medusa ransomware since the beginning of its activities in June 2021. Medusa is predominantly propagated through the exploitation of ...