China-Linked Storm-1175 Hackers Deploy New StormEncryptor Ransomware Exploiting N-central Flaw

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. This marks a shift from the adversary’s previous use of Medusa ransomware, according to the Microsoft Threat Intelligence Team.

StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory. The exact vulnerability exploited by the threat actor is unclear, but it likely involves the exploitation of CVE-2026-18577, a newly disclosed security flaw in N-able N‑central, to obtain initial access.

The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged these vulnerabilities as actively exploited in the wild.

Storm-1175 has a history of deploying Medusa ransomware after exploiting security flaws in various software, including Mirth Connect and Fortinet FortiClient EMS. The group is known for weaponizing a combination of zero-days and N-day vulnerabilities to carry out high-velocity attacks, taking advantage of the window between vulnerability disclosure and patch adoption.

In this new activity, Storm-1175’s post-compromise behavior includes the abuse of remote monitoring and management tools such as AnyDesk or SimpleHelp, as well as LSASS dumping using Mimikatz. The group has been observed rapidly moving from initial access to data exfiltration and ransomware deployment, often within a few days, highlighting the urgency for customers to apply patches promptly.

For further details, refer to the report by The Hacker News.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...