Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-06 and was added to the RWP archive on 2026-09-07.

Daily Top · Ransomware

Storm-1175's Medusa business was the patch gap on the internet, measured in hours

Microsoft's April 2026 Storm-1175 brief is the affiliate playbook behind GoAnywhere and a dozen other N-days — healthcare, education, and finance hit in AU/UK/US, sometimes encrypted inside 24 hours.

RWP Ventures · 2026-09-07 · event 2026-04-06 · 2 min read · priority 8.7

Bottom line up front

CONFIRMED On 6 April 2026 Microsoft described Storm-1175 as a high-velocity Medusa affiliate that lives in the week between CVE disclosure and your change window. Microsoft has seen it exploit more than 16 vulnerabilities since 2023, mixing N-days (ScreenConnect CVE-2024-1709, Exchange, CrushFTP CVE-2025-31161) with zero-days including GoAnywhere CVE-2025-10035 and SmarterMail CVE-2026-23760, both used about a week before public disclosure. After access: RMM (SimpleHelp), Rclone, then Medusa (Gaze.exe), sometimes inside 24 hours. Recent Microsoft-observed victims clustered in healthcare, education, professional services, and finance in Australia, the UK, and the US.

This is the same actor as the October 2025 GoAnywhere post already in this archive. That post is the CVE. This one is the operating system of the affiliate. Not merged.

Historical backfill of 6 April 2026 reporting; added 7 September 2026.

What happened

Storm-1175 does not need a new encryptor. It needs a scanner and a calendar. Ampcus's recap of Microsoft's list adds Ivanti, TeamCity, SAP, BeyondTrust, SimpleHelp as the kind of perimeter it prefers. CISA's Medusa advisory, later updated, cites the Microsoft blog and the gaze.exe encryptor behavior (service stop, shadow-copy delete, AES-256).

A later August 2026 BleepingComputer piece says the same cluster moved to StormEncryptor after an N-central CVE. That is a sequel, not this article.

Why it mattered

If your internet-facing RMM, MFT, or mail appliance is unpatched for a week, you are in their TAM. Healthcare's 24-hour encryption window is why "we'll patch next Saturday" is an incident-response decision.

Who / what was affected

Microsoft-named sectors and countries above. OT: UNKNOWN / not claimed. A hospital ransomware event can stop clinical systems without being a PLC compromise.

Technical context

Hunt SimpleHelp under web-app processes, Rclone, new domain admins, PDQ/GPO for ransomware staging. Exposure reduction beats YARA.

Exploitation / threat status at the time

CONFIRMED Microsoft tempo, Medusa payload, mixed N-day/0-day.

REPORTED 16+ CVEs since 2023 as Microsoft-observed.

What defenders should have done

  1. Emergency SLA for internet-facing N-days measured in hours.
  2. Take admin interfaces off the internet.
  3. Assume Medusa if those apps were live unpatched; hunt, don't wait for the note.

RWP assessment

Confidence: High on Microsoft's actor sketch. This is volume crime against your DMZ.

Defensive actions

  1. Weekly external scan of MFT/RMM/VPN/mail.
  2. Tamper-protect EDR; Medusa kills backup services.
  3. 24-hour tabletop from "CVE tweet" to "appliance isolated."

Sources

  1. Microsoft Threat Intelligence — Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa operations
  2. Ampcus Cyber — Storm-1175 exploits patch gaps to deploy Medusa
  3. CISA — #StopRansomware: Medusa Ransomware (AA25-071A, updated)