# Microsoft links China-based Storm-1175 to Medusa ransomware zero-day attacks

_Monday, April 6, 2026 at 6:03 PM EDT · Cybersecurity · Latest · Tier 1 — Major_

![Microsoft links China-based Storm-1175 to Medusa ransomware zero-day attacks — Primary](https://www.bleepstatic.com/content/hl-images/2025/03/12/Medusa_headpic.jpg)

Microsoft has attributed a series of ransomware attacks exploiting zero-day and n-day vulnerabilities to Storm-1175, a China-based financially motivated cybercriminal group deploying Medusa ransomware payloads. The threat actor has conducted high-velocity attacks targeting unpatched systems, according to Microsoft's threat intelligence division, which identified the group's operational tempo and technical sophistication as distinguishing characteristics. The disclosure adds to growing concerns about the convergence of state-affiliated and criminal cyber operations, with Storm-1175 representing a category of threat actor that maintains infrastructure and capabilities spanning both espionage and profit-driven activities. Microsoft's analysis indicates the group has rapidly incorporated newly disclosed vulnerabilities into attack chains, reducing the window available for defensive patching. The Medusa ransomware variant has been observed in attacks against critical infrastructure, healthcare, and manufacturing sectors globally. Security researchers note that the group's ability to operationalize zero-days within days of disclosure suggests access to vulnerability research capabilities or underground markets for exploit code.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/microsoft-links-medusa-ransomware-affiliate-to-zero-day-attacks/)

---
Canonical: https://techandbusiness.org/newswire/i18Da340mO8Zdpvc5umYcN
Retrieved: 2026-04-21T23:28:02.247Z
Publisher: Tech & Business (techandbusiness.org)
