New StormEncryptor Ransomware Deployed by China-Linked Hackers, Likely Exploiting N-central Vulnerability

New StormEncryptor Ransomware Deployed by China-Linked Hackers, Likely Exploiting N-central Vulnerability

Microsoft has revealed that a financially driven threat group known as Storm-1175, associated with China, has introduced a new ransomware variant called StormEncryptor, which had not been documented before.

This new ransomware signifies a departure from the adversary’s earlier use of Medusa ransomware, according to the Microsoft Threat Intelligence Team.

According to Microsoft’s posts on Bluesky, “StormEncryptor is developed in C++ and adds the .encrypted file extension to the files it encrypts.” It also creates a ransom note titled !!!README_FIRST!!!.txt in every directory it scans.

While the specific vulnerability that the threat actor exploited in this operation remains uncertain, Microsoft suggested that it likely involves the exploitation of CVE-2026-18577, a recently revealed security weakness in N-able N-central, to gain initial access.

This vulnerability is considered a patch bypass for CVE-2026-18556, both of which enable authentication bypass and account takeover in affected versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified these vulnerabilities as being actively exploited.

Storm-1175 is the designation given to a China-based threat actor known for deploying Medusa ransomware after taking advantage of security vulnerabilities in Mirth Connect (CVE-2023-37679, CVE-2023-43208), ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708), JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199), and Fortinet FortiClient EMS (CVE-2023-48788).

In an analysis released in October 2025, Microsoft also linked this threat actor to the exploitation of a critical security flaw in Fortra GoAnywhere (CVE-2025-10035) to enable the deployment of Medusa ransomware.

According to the Windows maker, the group utilizes a mix of zero-day and N-day vulnerabilities to execute rapid attacks and infiltrate vulnerable internet-facing systems by exploiting the gap between the disclosure of vulnerabilities and the implementation of patches.

Microsoft further noted that in this latest activity, Storm-1175’s behavior after compromising systems includes the misuse of remote monitoring and management tools such as AnyDesk or SimpleHelp, using Advanced IP Scanner for discovery, and dumping LSASS with Mimikatz.

Storm-1175 has been seen quickly transitioning from initial access to data exfiltration and ransomware deployment, often within a matter of days, highlighting the urgency for customers to apply patches promptly.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top