Ransomware

Storm-1175 actor deploys new StormEncryptor ransomware after N-central vulnerability exploitation

As reported by Bleeping Computer, a financially motivated threat actor, previously linked to the Medusa ransomware operation and tracked as Storm-1175, has begun deploying a new ransomware strain named StormEncryptor.

Microsoft Threat Intelligence indicates that Storm-1175, believed to be China-based, likely exploited an authentication-bypass vulnerability (CVE-2026-18577) in N-able's N-central remote monitoring and management tool to gain initial access. This marks the actor's first observed activity since April 2026 and a departure from their previous use of Medusa ransomware. StormEncryptor is a C++ malware that appends the ".encrypted" extension to files and leaves a ransom note demanding payment within three days, threatening data leakage if not met. The attackers utilized tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for lateral movement and credential theft.

Microsoft warns that Storm-1175 operates with speed, moving rapidly from compromise to data exfiltration and ransomware deployment. N-able has released a hotfix for the N-central vulnerability, urging customers to apply it immediately and check for signs of compromise.

Source: Bleeping Computer

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds