Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. This marks a shift from the adversary’s previous use of Medusa ransomware, according to the Microsoft Threat Intelligence Team.
StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory. The exact vulnerability exploited by the threat actor is unclear, but it likely involves the exploitation of CVE-2026-18577, a newly disclosed security flaw in N-able N‑central, to obtain initial access.
The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged these vulnerabilities as actively exploited in the wild.
Storm-1175 has a history of deploying Medusa ransomware after exploiting security flaws in various software, including Mirth Connect and Fortinet FortiClient EMS. The group is known for weaponizing a combination of zero-days and N-day vulnerabilities to carry out high-velocity attacks, taking advantage of the window between vulnerability disclosure and patch adoption.
In this new activity, Storm-1175’s post-compromise behavior includes the abuse of remote monitoring and management tools such as AnyDesk or SimpleHelp, as well as LSASS dumping using Mimikatz. The group has been observed rapidly moving from initial access to data exfiltration and ransomware deployment, often within a few days, highlighting the urgency for customers to apply patches promptly.
For further details, refer to the report by The Hacker News.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


