A financially driven threat actor, previously linked to the Medusa ransomware group, has begun using a new ransomware variant known as StormEncryptor.
Microsoft Threat Intelligence is monitoring this actor under the designation Storm-1175 and indicates that the recent attacks were likely preceded by the exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool.
Storm-1175 is thought to be a threat actor based in China. This actor was formerly associated with Medusa ransomware, targeting systems through zero-day and n-day vulnerabilities in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.
According to Microsoft, the deployment of StormEncryptor signifies the first activity observed from Storm-1175 since April 2026, indicating a departure from the previously utilized Medusa ransomware.
Researchers have identified StormEncryptor as C++ malware that appends the “.encrypted” extension to encrypted files and places a ransom note titled ‘!!!README_FIRST!!!.txt’ in every directory scanned.
The ransom note provides victims with a three-day window to contact the attacker and negotiate a ransom payment; otherwise, the stolen data will be leaked online.
Upon infiltrating the target network, the attacker employed AnyDesk or SimpleHelp for remote management, utilized Advanced IP Scanner for network discovery, and leveraged the Mimikatz tool to extract credentials from the Local Security Authority Subsystem Service (LSASS) process.
Microsoft warns that Storm-1175 acts swiftly, moving from initial compromise to data theft and ransomware deployment, urging system administrators managing self-hosted N-central servers to take prompt measures to secure their systems.
“This threat actor is known to quickly transition from initial access to data exfiltration and ransomware deployment, often within a few days,” Microsoft cautioned.
Organizations are advised to monitor for Storm-1175 activity and to apply security patches as soon as possible.
N-able addressed the CVE-2026-18577 vulnerability with a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch without delay.
N-able has previously recommended that administrators look for signs of compromise, such as an svchost.exe file in users’ Documents folders, a registered service named Cloudflared, and inbound connections from the IP addresses mentioned in the advisory.
Test every layer before attackers do. Security teams log 54% of successful attacks but only alert on 14%. The remainder go undetected in your environment.
The Picus whitepaper illustrates how breach and attack simulation can test your SIEM and EDR rules, preventing threats from evading detection.
Get the whitepaper.
Source: Original article
