Storm-1175
- First seen
- 2023-09-01 00:00:00
- Origin
- CN
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:23:27
Targeted industries: financial-services technology-and-telecommunications
Context
Storm-1175 is a cybercriminal group known for deploying Medusa ransomware and exploiting public-facing applications for initial access. They have been observed exploiting a critical deserialization vulnerability in GoAnywhere MFT, tracked as CVE-2025-10035, which could lead to command injection and potential RCE. Microsoft Defender researchers identified exploitation activity aligned with TTPs attributed to Storm-1175, including the use of post-compromise techniques that involve creating a group named “ESX Admins” in the domain.
Exploited vulnerabilities
- CVE-2025-10035 (vulnerability)
Reports & references
- Microsoft — Investigating Active Exploitation Of Cve 2025 10035 Goanywhere Managed File Transfer Vulnerability (report)
- raw.githubusercontent.com — Microsoftmapping (report)