INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
| 2026-08-13 08:09 CRITICAL HIGHExecutive Summary AI-generated
The threat actor, Storm-1175, has begun using a new ransomware strain called StormEncryptor in its latest attacks. This marks an evolution in the group's tactics as they exploit newly disclosed vulnerabilities before organizations can patch them. The attackers' speed and efficiency are highlighted by their ability to deploy ransomware in as little as one day, targeting sectors such as healthcare, education, finance, and services across the US, UK, and Australia. Microsoft has confirmed that China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa with this latest threat. The group's use of tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for remote access, Advanced IP Scanner to map networks, and LSASS credentials dumping suggests their sophistication in exploiting vulnerabilities. This incident data indicates a growing concern as the attackers continue to adapt and exploit newly disclosed vulnerabilities, necessitating rapid patching and monitoring to prevent further attacks.
Technical Mitigations AI-generated
* Implement a patching policy for all vulnerable systems and software as soon as possible to prevent exploitation of newly disclosed vulnerabilities.
* Conduct regular security audits and vulnerability assessments to identify potential entry points for attackers, and prioritize remediation efforts accordingly.
* Use multi-factor authentication (MFA) whenever possible to reduce the attack surface and make it more difficult for attackers to gain initial access.
* Implement a secure remote management (RMM) tool or software that can detect and respond to ransomware attacks in real-time, such as PDQ Deployer or Impacket.
* Monitor network traffic and system logs closely for signs of suspicious activity, and have incident response plans in place to quickly contain and mitigate ransomware infections.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2023-37679CVE-2023-37679
CVE-2025-10035CVE-2025-10035
CVE-2024-27199CVE-2024-27199
CVE-2024-27198CVE-2024-27198
CVE-2026-18577CVE-2026-18577
CVE-2023-43208CVE-2023-43208
CVE-2026-18556CVE-2026-18556
CVE-2024-1708CVE-2024-1708
CVE-2023-48788CVE-2023-48788
CVE-2024-1709CVE-2024-1709
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
financefinance
educationeducation
healthcarehealthcare
Incident Timeline
October 2025
Threat actors used Fortra GoAnywhere to exploit CVE-2025-10035, a critical security vulnerability.
Click on any entity below to view its context and source!
tactic
Ransomware
In an analysis published in October 2025, Microsoft also
attributed
the threat actor to the exploitation of a critical security vulnerability impacting Fortra GoAnywhere (CVE-2025-10035) to facilitate the deployment of Medusa ransomware.
vulnerability
CVE-2025-10035
In an analysis published in October 2025, Microsoft also
attributed
the threat actor to the exploitation of a critical security vulnerability impacting Fortra GoAnywhere (CVE-2025-10035) to facilitate the deployment of Medusa ransomware.
organisation
Fortra GoAnywhere
In an analysis published in October 2025, Microsoft also
attributed
the threat actor to the exploitation of a critical security vulnerability impacting Fortra GoAnywhere (CVE-2025-10035) to facilitate the deployment of Medusa ransomware.
April 2026
Storm-1175 deployed StormEncryptor, a new ransomware.
Click on any entity below to view its context and source!
tactic
Ransomware
“Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use,” Microsoft states.
attribution
Microsoft Threat Intelligence
“Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use,” Microsoft states.
attribution
Microsoft
“Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use,” Microsoft states.
August 2, 2026
Threat actors used CVE-2026-18577 authentication bypass vulnerability in N-able to target StormEncryptor ransomware.
Click on any entity below to view its context and source!
tactic
Ransomware
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the
CVE-2026-18577
authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.”
wrote
Microsoft on X.
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
vulnerability
CVE-2026-18577
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the
CVE-2026-18577
authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.”
wrote
Microsoft on X.
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
tactic
T1588.006 - Vulnerabilities
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the
CVE-2026-18577
authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.”
wrote
Microsoft on X.
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
attribution
KEV
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the
CVE-2026-18577
authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.”
wrote
Microsoft on X.
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
August 2
Threat actors used a previously unknown vulnerability (CVE-2026-18577) in StormEncryptor ransomware to gain access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-18577
“Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”
N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.
infrastructure
2026.3
“Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”
N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.
infrastructure
2026.3.1
“Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”
N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.
organisation
CVE-2026
“Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”
N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.
general_metric
2026.3 HF1
“Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”
N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.
August 3, 2026
Microsoft confirmed the incident through Microsoft on August 13, 2026.
Click on any entity below to view its context and source!
tactic
Ransomware
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the
CVE-2026-18577
authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.”
wrote
Microsoft on X.
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
vulnerability
CVE-2026-18577
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the
CVE-2026-18577
authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.”
wrote
Microsoft on X.
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
tactic
T1588.006 - Vulnerabilities
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the
CVE-2026-18577
authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.”
wrote
Microsoft on X.
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
attribution
KEV
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the
CVE-2026-18577
authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.”
wrote
Microsoft on X.
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
Aug 10, 2026
Threat actors used StormEncryptor ransomware to target a previously compromised Medusa affiliate.
2026/08/13
Storm-1175 used a newly disclosed security flaw in N-central to obtain initial access.
Click on any entity below to view its context and source!
organisation
Microsoft
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks.
Ransomware / Cybercrime
Microsoft has disclosed that
Storm-1175
, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called
StormEncryptor
.
StormEncryptor ransom note
Source: Microsoft
After gaining access to the target network, the attacker used AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and the Mimikatz tool to dump credentials from the Local Security Authority Subsystem Service (LSASS) process.
organisation
Storm-1175
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks.
Storm-1175 is the name assigned to a
China-based threat actor
with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (
CVE-2023-37679
,
CVE-2023-43208
), ConnectWise ScreenConnect (
CVE-2024-1709
,
CVE-2024-1708
), JetBrains TeamCity (
CVE-2024-27198
,
CVE-2024-27199
), and Fortinet FortiClient EMS (
CVE-2023-48788
).
Storm-1175 is believed to be a China-based threat actor.
organisation
StormEncryptor
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks.
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
organisation
Ransomware / Cybercrime
Ransomware / Cybercrime
Microsoft has disclosed that
Storm-1175
, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called
StormEncryptor
.
organisation
Microsoft Exchange
It was previously linked to Medusa ransomware, targeting systems via
zero-day and n-day flaws
in various products, including
GoAnywhere MFT
, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.
Since 2023, the group has targeted many platforms, including Microsoft Exchange, Ivanti, ConnectWise, JetBrains, and others.
infrastructure
Smartermail
It was previously linked to Medusa ransomware, targeting systems via
zero-day and n-day flaws
in various products, including
GoAnywhere MFT
, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.
organisation
MFT
It was previously linked to Medusa ransomware, targeting systems via
zero-day and n-day flaws
in various products, including
GoAnywhere MFT
, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.
organisation
Invanti Connect Secure
It was previously linked to Medusa ransomware, targeting systems via
zero-day and n-day flaws
in various products, including
GoAnywhere MFT
, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.
organisation
JetBrains TeamCity
It was previously linked to Medusa ransomware, targeting systems via
zero-day and n-day flaws
in various products, including
GoAnywhere MFT
, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.
Storm-1175 is the name assigned to a
China-based threat actor
with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (
CVE-2023-37679
,
CVE-2023-43208
), ConnectWise ScreenConnect (
CVE-2024-1709
,
CVE-2024-1708
), JetBrains TeamCity (
CVE-2024-27198
,
CVE-2024-27199
), and Fortinet FortiClient EMS (
CVE-2023-48788
).
organisation
CVE-2023-43208
Storm-1175 is the name assigned to a
China-based threat actor
with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (
CVE-2023-37679
,
CVE-2023-43208
), ConnectWise ScreenConnect (
CVE-2024-1709
,
CVE-2024-1708
), JetBrains TeamCity (
CVE-2024-27198
,
CVE-2024-27199
), and Fortinet FortiClient EMS (
CVE-2023-48788
).
organisation
CVE-2023-48788
Storm-1175 is the name assigned to a
China-based threat actor
with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (
CVE-2023-37679
,
CVE-2023-43208
), ConnectWise ScreenConnect (
CVE-2024-1709
,
CVE-2024-1708
), JetBrains TeamCity (
CVE-2024-27198
,
CVE-2024-27199
), and Fortinet FortiClient EMS (
CVE-2023-48788
).
organisation
ConnectWise ScreenConnect
Storm-1175 is the name assigned to a
China-based threat actor
with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (
CVE-2023-37679
,
CVE-2023-43208
), ConnectWise ScreenConnect (
CVE-2024-1709
,
CVE-2024-1708
), JetBrains TeamCity (
CVE-2024-27198
,
CVE-2024-27199
), and Fortinet FortiClient EMS (
CVE-2023-48788
).
organisation
Fortinet FortiClient EMS
Storm-1175 is the name assigned to a
China-based threat actor
with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (
CVE-2023-37679
,
CVE-2023-43208
), ConnectWise ScreenConnect (
CVE-2024-1709
,
CVE-2024-1708
), JetBrains TeamCity (
CVE-2024-27198
,
CVE-2024-27199
), and Fortinet FortiClient EMS (
CVE-2023-48788
).
organisation
AnyDesk
StormEncryptor ransom note
Source: Microsoft
After gaining access to the target network, the attacker used AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and the Mimikatz tool to dump credentials from the Local Security Authority Subsystem Service (LSASS) process.
In recent attacks, the group used tools such as AnyDesk and SimpleHelp for remote access, Advanced IP Scanner to map networks, and Mimikatz to dump LSASS credentials.
"In this new activity, Storm-1175's post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz," it added.
organisation
SimpleHelp
StormEncryptor ransom note
Source: Microsoft
After gaining access to the target network, the attacker used AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and the Mimikatz tool to dump credentials from the Local Security Authority Subsystem Service (LSASS) process.
In recent attacks, the group used tools such as AnyDesk and SimpleHelp for remote access, Advanced IP Scanner to map networks, and Mimikatz to dump LSASS credentials.
"In this new activity, Storm-1175's post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz," it added.
organisation
Advanced IP Scanner
StormEncryptor ransom note
Source: Microsoft
After gaining access to the target network, the attacker used AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and the Mimikatz tool to dump credentials from the Local Security Authority Subsystem Service (LSASS) process.
In recent attacks, the group used tools such as AnyDesk and SimpleHelp for remote access, Advanced IP Scanner to map networks, and Mimikatz to dump LSASS credentials.
organisation
the Local Security Authority Subsystem Service
StormEncryptor ransom note
Source: Microsoft
After gaining access to the target network, the attacker used AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and the Mimikatz tool to dump credentials from the Local Security Authority Subsystem Service (LSASS) process.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, China)
organisation
Ivanti
Since 2023, the group has targeted many platforms, including Microsoft Exchange, Ivanti, ConnectWise, JetBrains, and others.
organisation
ConnectWise
Since 2023, the group has targeted many platforms, including Microsoft Exchange, Ivanti, ConnectWise, JetBrains, and others.
organisation
JetBrains
Since 2023, the group has targeted many platforms, including Microsoft Exchange, Ivanti, ConnectWise, JetBrains, and others.
infrastructure
Windows
“Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including:
The attackers also chain multiple exploits to achieve deeper access, such as remote code execution, and have targeted both Windows and Linux systems.
The group, per the Windows maker,
weaponizes
a combination of zero-days and N-day vulnerabilities to carry out high-velocity attacks and break into susceptible internet-facing systems by taking advantage of the window between vulnerability disclosure and patch adoption.
infrastructure
Linux
“Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including:
The attackers also chain multiple exploits to achieve deeper access, such as remote code execution, and have targeted both Windows and Linux systems.
The group also targets Linux systems and has used zero-day flaws before public disclosure, showing advanced skills.
organisation
PsExec
After gaining access, it installs web shells or remote tools, creates admin accounts, and moves laterally using tools like PowerShell, PsExec, RDP, and Cloudflare tunnels.
organisation
RDP
After gaining access, it installs web shells or remote tools, creates admin accounts, and moves laterally using tools like PowerShell, PsExec, RDP, and Cloudflare tunnels.
organisation
Cloudflare
After gaining access, it installs web shells or remote tools, creates admin accounts, and moves laterally using tools like PowerShell, PsExec, RDP, and Cloudflare tunnels.
organisation
RMM
It also abuses legitimate RMM tools and software like PDQ Deployer and Impacket to spread across networks.
organisation
PDQ Deployer
It also abuses legitimate RMM tools and software like PDQ Deployer and Impacket to spread across networks.
organisation
Cloudflared
N-able
previously recommended
admins to check for signs of compromise such as an
svchost.exe
file in the Documents folders of users' device, a registered service named Cloudflared, and inbound connections from the IP addresses listed in the advisory.
organisation
IP
N-able
previously recommended
admins to check for signs of compromise such as an
svchost.exe
file in the Documents folders of users' device, a registered service named Cloudflared, and inbound connections from the IP addresses listed in the advisory.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Tactical Metrics
Metrics
infrastructure
Ivanti
Affected Product
Click for context!
Since 2023, the group has targeted many platforms, including Microsoft Exchange, Ivanti, ConnectWise, JetBrains, and others.
Metrics
infrastructure
Windows
Affected Product
“Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including:
The attackers also chain multiple exploits to achieve deeper access, such as remote code execution, and have targeted both Windows and Linux systems.
The group, per the Windows maker,
weaponizes
a combination of zero-days and N-day vulnerabilities to carry out high-velocity attacks and break into susceptible internet-facing systems by taking advantage of the window between vulnerability disclosure and patch adoption.
Metrics
infrastructure
Linux
Affected Product
“Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including:
The attackers also chain multiple exploits to achieve deeper access, such as remote code execution, and have targeted both Windows and Linux systems.
The group also targets Linux systems and has used zero-day flaws before public disclosure, showing advanced skills.
Metrics
infrastructure
Smartermail
Affected Product
It was previously linked to Medusa ransomware, targeting systems via
zero-day and n-day flaws
in various products, including
GoAnywhere MFT
, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.
Metrics
infrastructure
2026.3
Software Version
“Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”
N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.
Metrics
infrastructure
2026.3.1
Software Version
“Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”
N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.
Intelligence Sources
BleepingComputer
2026-08-10
New StormEncryptor ransomware used by former Medusa affiliate
BleepingComputer
The Hacker News
2026-08-10
Security Affairs
2026-08-13
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-13T10:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
30x
organisation
Identified Entity
Microsoft
entity
10x
vulnerability
Exploited CVE
CVE-2026-18577
cve
7x
timeline
Temporal Reference
August 2, 2026
date
7x
attribution
Attributing Entity
the Cybersecurity and Infrastructure Security Agency
authority
4x
target region
Target Country
China
country
4x
infrastructure
Affected Product
Ivanti
software
3x
tactic
Cyber Operation Type
Ransomware
tactic
3x
industry
Targeted Sector
Healthcare
sector
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
infrastructure
Software Version
2026.3
version
2x
general metric
%
54
%
2x
general metric
Aug
10
aug
Contextual Telemetry
Context Block
5 METRICS
source region
Origin Country
China
country
general metric
Hours
24
hours
malware
Offensive Tool
Mimikatz
tool
general metric
Vulnerabilities
16
vulnerabilities
general metric
Hf1
2,026
hf1
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.