CARDS
CARDS
This card connects two source-bounded layers: broad multi-actor exploitation of the 2024 ScreenConnect authentication-bypass and path-traversal flaws, and Microsoft’s later named Storm-1175 campaign chain in which vulnerable web-facing assets, including ScreenConnect, can lead to credential theft, lateral movement, data exfiltration, security tampering, and Medusa ransomware. It does not assert that every 2024 ScreenConnect intrusion was Storm-1175 activity.
Last updated Jul 18, 2026, 7:30 PM EDT
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
This is a connected exposure-and-campaign card, not a claim that one actor ran every ScreenConnect intrusion. CVE-2025-3935, the 2025 ConnectWise nation-state event, and 2026 rogue-client installation campaigns are separate tracks unless incident evidence establishes a connection.
Evidence Controls
IntelliOS
Citations