Medusa
Also known as Storm-1175
Reports
8
First seen
Oct 8, 2024
Last seen
Aug 12, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
United Kingdom ×1
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×6T1190 Exploit Public-Facing Application ×6T1005 Data from Local System ×3T1041 Exfiltration Over C2 Channel ×3T1003 OS Credential Dumping ×3T1018 Remote System Discovery ×3T1219 Remote Access Software ×3T1133 External Remote Services ×3T1021 Remote Services ×2T1566 Phishing ×2T1078 Valid Accounts ×2T1021.002 SMB/Windows Admin Shares ×2
Indicators
filename ×50cve ×20
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2026-18577 (exploited)CVE-2026-39987 (exploited)CVE-2024-1709 (exploited)CVE-2024-1708 (exploited)CVE-2024-27198 (exploited)CVE-2024-27199 (exploited)CVE-2024-3721 (exploited)CVE-2025-10035 (exploited)CVE-2026-1340 (exploited)CVE-2026-18556 (exploited)CVE-2026-33032 (exploited)CVE-2026-35616 (exploited)CVE-2023-37679 (exploited)CVE-2026-41940 (exploited)CVE-2023-43208 (exploited)CVE-2023-48788 (exploited)
Recent reports
High