Storm-0501’s evolving techniques lead to cloud-based ransomware
Microsoft Threat Intelligence has observed financially motivated threat actor Storm-0501 continuously evolving their campaigns to achieve sharpened focus on cloud-based tactics, techniques, and...
View ArticleInvestigating active exploitation of CVE-2025-10035 GoAnywhere Managed File...
In this article Vulnerability analysis Exploitation activity by Storm-1175Mitigation and protection guidanceMicrosoft Defender XDR detectionsIndicators of compromise On September 18, 2025, Fortra...
View ArticleStorm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa...
In this article Storm-1175’s rapid attack chain: From initial access to impactMitigation and protection guidanceMicrosoft Defender detectionsIndicators of compromise The financially motivated...
View ArticleExposing Fox Tempest: A malware-signing service operation
In this article Fox Tempest’s role and impactFox Tempest’s malware signing as a service infrastructureDefending against Fox Tempest-enabled attacksMicrosoft Defender detectionsIndicators of compromise...
View ArticleStorm-0501: Ransomware attacks expanding to hybrid cloud environments
August 27, 2025 update: Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using...
View ArticleCyber Signals Issue 8 | Education under siege: How cybercriminals target...
Introduction | Security snapshot | Threat briefingDefending against attacks | Expert profile Education is essentially an “industry of industries,” with K-12 and higher education enterprises handling...
View ArticleExploitation of CLFS zero-day leads to ransomware activity
Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a zero-day elevation of privilege vulnerability in the...
View ArticleUnveiling RIFT: Enhancing Rust malware analysis through pattern matching
Today, Microsoft Threat Intelligence Center is excited to announce the release of RIFT, a tool designed to assist malware analysts automate the identification of attacker-written code within Rust...
View ArticleThe Gentlemen ransomware: Dissecting a self-propagating Go encryptor
In this article Pre-encryptionFile encryptionPost-encryptionDefending against The Gentlemen ransomwareMicrosoft Defender detections and hunting guidanceIndicators of compromise Ransomware that...
View ArticleDeadLock ransomware: Breaking down a Rust-based encryptor with decentralized...
In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially...
View Article