Storm-1175 exploits new vulnerabilities and encrypts within a week

Microsoft has published an analysis of the China-linked threat actor Storm-1175, focused on how quickly it adopts new vulnerabilities. According to Microsoft, the actor has been seen exploiting vulnerabilities as early as one day after disclosure, and in some cases as zero-days a full week before disclosure. After initial compromise it exfiltrates data before deploying Medusa ransomware, enabling double extortion through both holding data hostage and threatening to leak or sell it. The time from compromise to encryption is often under a week, sometimes as little as a day.

What this means for your organisation

Monthly patch windows are no longer sufficient for internet-facing services. When less than a week passes from intrusion to encryption, there is also little room to detect anything in between if monitoring is only reviewed during office hours. The consequence is twofold: operational downtime and a data leak that can trigger both notification duties and reputational damage.

Berigo recommends

  • Treat internet-facing services as their own category with a shorter patching deadline than the rest.
  • Ensure monitoring alerts are actually seen outside office hours.
  • Test that backups restore, and that they cannot be deleted by whoever compromises production.
  • Rehearse the data leak half of a ransomware event, not only the recovery half.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch