New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.

Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool.

Storm-1175 is believed to be a China-based threat actor. It was previously linked to Medusa ransomware, targeting systems via zero-day and n-day flaws in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.

“Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use,” Microsoft states.

The researchers found that StormEncryptor is a C++ malware that appends encrypted files with the “.encrypted” filename extension and drops a ransom note named ‘!!!README_FIRST!!!.txt’ into every scanned directory.

The ransom note gives victims three days to reach out to the attacker and negotiate a ransom payment. Alternatively, the stolen data would be leaked online.

After gaining access to the target network, the attacker used AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and the Mimikatz tool to dump credentials from the Local Security Authority Subsystem Service (LSASS) process.

Microsoft says that Storm-1175 moves quickly from initial compromise to stealing data and deploying the locker, urging system administrators managing self-hosted N-central servers to take immediate action to secure the systems.

“This threat actor is known to rapidly move from initial access to data exfiltration and ransomware deployment, often within a few days,” warned Microsoft.

“Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”

N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.

N-able previously recommended admins to check for signs of compromise such as an svchost.exe file in the Documents folders of users’ device, a registered service named Cloudflared, and inbound connections from the IP addresses listed in the advisory.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

DoppelPaymer ransomware hits Newcastle University, leaks data

Ransom Cartel ransomware creator sentenced to 16 years in prison

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

West Pharmaceutical says hackers stole data, encrypted systems

Hackers breach TrueConf to trojanize client installers with backdoors

LexisNexis shuts down services after suspicious activity on servers

Valve notifies Steam hardware customers of a data breach

Overdue a password health-check? Audit your Active Directory for free

Webinar: Shadow AI in 2026 (and how attackers are taking advantage)

AI is a data-breach time bomb: Read the new report

See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.

See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.