Microsoft has revealed that Storm-1175, a threat actor associated with China, has introduced a new ransomware known as StormEncryptor. This marks a departure from their previous use of the Medusa ransomware. According to the Microsoft Threat Intelligence Team, StormEncryptor is written in C++ and appends the .encrypted extension to affected files. It also deposits a ransom note titled !!!README_FIRST!!!.txt in each directory it scans.
While the specific vulnerability leveraged by Storm-1175 remains uncertain, Microsoft suggests it likely involves exploiting CVE-2026-18577, a recently identified flaw in N-able N-central, to gain initial access. This flaw is believed to be a patch bypass for CVE-2026-18556, both of which enable authentication bypass and account takeover in vulnerable versions. The U.S. Cybersecurity and Infrastructure Security Agency has flagged these vulnerabilities as actively exploited.
Storm-1175 is known for utilizing Medusa ransomware, having previously targeted vulnerabilities in Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS. Microsoft's analysis from October 2025 also linked the group to exploiting Fortra GoAnywhere's critical security vulnerability to deploy Medusa ransomware. The group is adept at using zero-day and N-day vulnerabilities, launching rapid attacks on internet-facing systems during the window between disclosure and patch implementation.
In their latest campaign, Storm-1175 has been using remote monitoring and management tools like AnyDesk and SimpleHelp, Advanced IP Scanner for network discovery, and Mimikatz for LSASS dumping. The group is known for swiftly escalating from initial access to data exfiltration and ransomware deployment, often completing these steps within days. This underscores the urgency for affected organizations to apply patches promptly.


