business / news / / TechRadar
Storm-1175 rapidly moves from access to ransomware deployment.
Storm-1175 can move from initial access to ransomware deployment in less than 24 hours.
KEY POINTS
- The group exploits both zero-day and n-day vulnerabilities, sometimes chaining multiple flaws together.
- Storm-1175 is not state-sponsored but operates independently for profit.
- They have exploited over 16 vulnerabilities across 10 products, including Microsoft Exchange and Ivanti.
- Storm-1175 disables antivirus and endpoint protection before deploying Medusa ransomware.
COMPANIES
Summarized by Newsio from TechRadar. How we summarize →