A highly motivated threat actor, previously linked to the notorious Medusa ransomware operation, has resurfaced with a new strain of malware called StormEncryptor. The attacker, tracked by Microsoft as “Storm-1175,” has been using this powerful tool to extort money from victims worldwide.
The bad news is that Storm-1175 is believed to be based in China and has already demonstrated the ability to rapidly move from initial compromise to data exfiltration and ransomware deployment. In fact, Microsoft warns that this threat actor can achieve all of these steps within just a few days. This speed and agility make them particularly challenging for security teams to track and contain.
To understand how StormEncryptor works, it’s essential to know that it is a C++ malware that uses an encryption algorithm to lock victims’ files and demand a ransom payment in exchange for the decryption key. The attackers append the “.encrypted” filename extension to encrypted files and drop a ransom note named “!!!README_FIRST!!!.txt” into every scanned directory on the compromised system.
The researchers found that, before deploying StormEncryptor, the attacker exploited an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool to gain access to the target network. They then used various tools for remote management, network discovery, and credential dumping, including AnyDesk or SimpleHelp, Advanced IP Scanner, and Mimikatz.
One of the most worrying aspects of this case is that Storm-1175 has shifted away from Medusa ransomware in favor of StormEncryptor. This change suggests that the threat actor may be refining their tactics to evade detection and maximize their profits. Microsoft notes that organizations should take immediate action to secure their self-hosted N-central servers, especially given the rapid pace at which this threat actor operates.
Fortunately, N-able has already released a hotfix (2026.3 HF1/build 2026.3.1.7) for the CVE-2026-18577 vulnerability on August 2, urging customers to install the patch as soon as possible. System administrators are also advised to monitor their systems for signs of compromise and apply security patches promptly.
In light of this threat, we urge our readers to take proactive steps to protect themselves against StormEncryptor. This includes staying up-to-date with the latest security patches and monitoring your systems for suspicious activity. Remember that a strong defense is often the best offense – test every layer of your security setup before attackers do.
Source: Bleeping Computer — 2026-08-10