China-Linked Storm-1175 Hackers Deploy New StormEncryptor Ransomware Exploiting N-central Flaw

Published:

spot_img

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. This marks a shift from the adversary’s previous use of Medusa ransomware, according to the Microsoft Threat Intelligence Team.

StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory. The exact vulnerability exploited by the threat actor is unclear, but it likely involves the exploitation of CVE-2026-18577, a newly disclosed security flaw in N-able N‑central, to obtain initial access.

The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged these vulnerabilities as actively exploited in the wild.

Storm-1175 has a history of deploying Medusa ransomware after exploiting security flaws in various software, including Mirth Connect and Fortinet FortiClient EMS. The group is known for weaponizing a combination of zero-days and N-day vulnerabilities to carry out high-velocity attacks, taking advantage of the window between vulnerability disclosure and patch adoption.

In this new activity, Storm-1175’s post-compromise behavior includes the abuse of remote monitoring and management tools such as AnyDesk or SimpleHelp, as well as LSASS dumping using Mimikatz. The group has been observed rapidly moving from initial access to data exfiltration and ransomware deployment, often within a few days, highlighting the urgency for customers to apply patches promptly.

For further details, refer to the report by The Hacker News.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

New York City Lawmakers Advocate for Legislation to Ban Facial Recognition Technology at Public Venues

Privacy advocates and musicians rallied outside Madison Square Garden on Friday, advocating for new legislation to ban facial-recognition technology at the venue and other...

Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability in New Campaign

Lazarus Group's Operation Dream Job Exploits Zero-Day Vulnerability in New Campaign In early 2026, Check Point Research began tracking a significant wave of cyberattacks under...

FreePBX Security Advisory AV26-818 Warns of Vulnerabilities in Multiple Products

Advisory Number: AV26-818Date Issued: August 14, 2026 FreePBX has issued a security advisory regarding vulnerabilities affecting several of its products. As of August 13, 2026,...

DeadLock Ransomware Leverages Polygon Smart Contracts for Enhanced Extortion Resilience

The ransomware group known as DeadLock has been observed utilizing decentralized infrastructure to enhance victim communications and data leak operations, thereby improving operational resilience....