CARDS
CARDS
This card connects two source-bounded layers: broad multi-actor exploitation of the 2024 ScreenConnect authentication-bypass and path-traversal flaws, and Microsoft’s later named Storm-1175 campaign chain in which vulnerable web-facing assets, including ScreenConnect, can lead to credential theft, lateral movement, data exfiltration, security tampering, and Medusa ransomware. It does not assert that every 2024 ScreenConnect intrusion was Storm-1175 activity.
Last updated Jul 18, 2026, 7:30 PM EDT
Evidence Boundary
Bottom Line Up Front
This card connects two source-bounded layers: broad multi-actor exploitation of the 2024 ScreenConnect authentication-bypass and path-traversal flaws, and Microsoft’s later named Storm-1175 campaign chain in which vulnerable web-facing assets, including ScreenConnect, can lead to credential theft, lateral movement, data exfiltration, security tampering, and Medusa ransomware. It does not assert that every 2024 ScreenConnect intrusion was Storm-1175 activity.[1][2][3][4]
Unauthorized remote administration can expose multiple managed customers, credentials, backup systems, directory services, sensitive data, and business operations. In the Storm-1175 chain, impact can include data theft, leak-site pressure, security-control tampering, and Medusa ransomware encryption.[1][2][3][4]
Inventory and restrict every ScreenConnect server; remediate all applicable KEVs; preserve setup, user, extension, command, session, identity, endpoint, backup, and network evidence; reset compromised trust; scope downstream customers separately; and hunt the full pre-encryption chain rather than stopping at patch verification.[1][2][3][4]
Decision Summary
This card connects two source-bounded layers: broad multi-actor exploitation of the 2024 ScreenConnect authentication-bypass and path-traversal flaws, and Microsoft’s later named Storm-1175 campaign chain in which vulnerable web-facing assets, including ScreenConnect, can lead to credential theft, lateral movement, data exfiltration, security tampering, and Medusa ransomware. It does not assert that every 2024 ScreenConnect intrusion was Storm-1175 activity.
The retained record scopes this as remote-management server exploitation / credential theft / double extortion / ransomware activity during February 2024 through July 2026 reporting window. Unauthorized remote administration can expose multiple managed customers, credentials, backup systems, directory services, sensitive data, and business operations. In the Storm-1175 chain, impact can include data theft, leak-site pressure, security-control tampering, and Medusa ransomware encryption.[1][2][3][4]
Inventory and restrict every ScreenConnect server; remediate all applicable KEVs; preserve setup, user, extension, command, session, identity, endpoint, backup, and network evidence; reset compromised trust; scope downstream customers separately; and hunt the full pre-encryption chain rather than stopping at patch verification.[1][2][3][4]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for the Microsoft-reported Storm-1175/Medusa chain and the Huntress-observed 2024 exploitation behaviors; attribution is not universal across ScreenConnect incidents..[1][2][3][4]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
This is a connected exposure-and-campaign card, not a claim that one actor ran every ScreenConnect intrusion. CVE-2025-3935, the 2025 ConnectWise nation-state event, and 2026 rogue-client installation campaigns are separate tracks unless incident evidence establishes a connection.
Evidence Controls
IntelliOS
Citations