Microsoft Threat Intelligence @threatintel.microsoft.com · Apr 6

The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have impacted healthcare organizations, as well as those in the education, professional services, and finance sectors in Australia, United Kingdom, and United States.

1 likes 1 replies

?

Replies

Microsoft Threat Intelligence · Apr 6

While Storm-1175's methodology aligns with the TTPs of many ransomware actors, analysis of their post-compromise tactics provides insight into how organizations can disrupt attackers even if they have gained initial access to a network.