China-Linked Storm-1175 Hackers Deploy New StormEncryptor Ransomware Exploiting N-central Flaw

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. This marks a shift from the adversary’s previous use of Medusa ransomware, according to the Microsoft Threat Intelligence Team.

StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory. The exact vulnerability exploited by the threat actor is unclear, but it likely involves the exploitation of CVE-2026-18577, a newly disclosed security flaw in N-able N‑central, to obtain initial access.

The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged these vulnerabilities as actively exploited in the wild.

Storm-1175 has a history of deploying Medusa ransomware after exploiting security flaws in various software, including Mirth Connect and Fortinet FortiClient EMS. The group is known for weaponizing a combination of zero-days and N-day vulnerabilities to carry out high-velocity attacks, taking advantage of the window between vulnerability disclosure and patch adoption.

In this new activity, Storm-1175’s post-compromise behavior includes the abuse of remote monitoring and management tools such as AnyDesk or SimpleHelp, as well as LSASS dumping using Mimikatz. The group has been observed rapidly moving from initial access to data exfiltration and ransomware deployment, often within a few days, highlighting the urgency for customers to apply patches promptly.

For further details, refer to the report by The Hacker News.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

FQ-42 Vengeance unmanned fighter aircraft displayed at AFA 2026

The FQ-42 Vengeance unmanned fighter aircraft, developed by General Atomics, was prominently displayed at the Air, Space and Cyber conference on September 14, 2026....

Meta’s AI Assistant Muse Exposed by Zero-Day Vulnerability, Prompting Amazon to Block Access

Meta's new AI assistant, Muse, has come under scrutiny following the discovery of a zero-day vulnerability that allows locally run applications and terminal commands...

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...