Storm-1175 Unleashes New StormEncryptor Ransomware, Exploiting N-able N-central Flaws
A financially motivated threat actor, **Storm-1175**, linked to China, has been observed deploying a novel ransomware strain dubbed **StormEncryptor**. This development marks a significant shift from their previous use of **Medusa ransomware** and is tied to the exploitation of critical vulnerabilities in **N-able N-central**.
Cybersecurity professionals and privacy-conscious users are urged to take immediate action as a new ransomware threat emerges. **Microsoft Threat Intelligence Team** has disclosed that **Storm-1175**, a sophisticated and financially motivated threat actor with suspected ties to China, is now deploying a previously undocumented ransomware variant named **StormEncryptor**.
This new ransomware signals a strategic pivot for **Storm-1175**, moving away from their prior reliance on **Medusa ransomware**.
### Diving into StormEncryptor
**StormEncryptor** is a C++-written ransomware that appends the `.encrypted` extension to compromised files. Upon encryption, it drops a ransom note titled `!!!README_FIRST!!!.txt` in every scanned directory, directing victims on how to proceed.

### Exploiting N-able N-central Vulnerabilities
While the precise initial access vector for these **StormEncryptor** campaigns remains under investigation, **Microsoft** suggests a high probability of exploitation targeting **CVE-2026-18577**. This newly disclosed security flaw impacts **N-able N-central** and is assessed to be a patch bypass for **CVE-2026-18556**. Both vulnerabilities enable authentication bypass and account takeover in susceptible versions.
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has already flagged these vulnerabilities as actively exploited in the wild, emphasizing the urgency of patching.
### Storm-1175's Track Record
**Storm-1175** has a well-documented history of exploiting critical security flaws in various widely used software to deploy **Medusa ransomware**. Their past targets include:
* **Mirth Connect** (**CVE-2023-37679**, **CVE-2023-43208**)
* **ConnectWise ScreenConnect** (**CVE-2024-1709**, **CVE-2024-1708**)
* **JetBrains TeamCity** (**CVE-2024-27198**, **CVE-2024-27199**)
* **Fortinet FortiClient EMS** (**CVE-2023-48788**)
In October 2025, **Microsoft** also linked **Storm-1175** to the exploitation of **CVE-2025-10035**, a critical vulnerability in **Fortra GoAnywhere**, to facilitate **Medusa ransomware** deployment.
### High-Velocity Attacks and Post-Compromise Behavior
The group is known for its aggressive approach, weaponizing a combination of zero-day and N-day vulnerabilities to execute high-velocity attacks. They strategically leverage the window between vulnerability disclosure and patch adoption to breach internet-facing systems.
In recent activity, **Storm-1175**'s post-compromise tactics have included the abuse of remote monitoring and management tools like **AnyDesk** or **SimpleHelp**, utilizing **Advanced IP Scanner** for network discovery, and performing **LSASS** dumping with **Mimikatz**.
**Storm-1175** typically moves rapidly from initial access to data exfiltration and ransomware deployment, often within a matter of days. This rapid operational tempo underscores the critical importance of applying security patches as soon as they become available.