Microsoft has revealed that Storm-1175, a financially motivated cybercriminal group with connections to China, is now deploying a previously unseen ransomware family called StormEncryptor, marking a notable evolution in the group's attack operations.
According to Microsoft's threat intelligence researchers, the emergence of StormEncryptor signals a departure from the threat actor's earlier reliance on Medusa ransomware, which had previously been the group's primary payload in numerous intrusion campaigns.
New Ransomware Variant Emerges
StormEncryptor is a newly identified ransomware strain developed in C++. Once executed on a victim system, the malware encrypts files and appends the extension “.encrypted” to affected data. It also creates a ransom note named “!!!README_FIRST!!!.txt” throughout compromised directories, providing victims with instructions from the attackers.
The ransomware appears to be specifically designed for rapid deployment following successful network compromise and data theft activities.
Suspected Initial Access Through N-able N-central Vulnerability
While Microsoft has not definitively confirmed the initial attack vector, investigators believe the campaign likely began with the exploitation of CVE-2026-18577, a recently disclosed vulnerability affecting N-able N-central Remote Monitoring and Management (RMM) software.
The flaw is considered a bypass of an earlier vulnerability, CVE-2026-18556, and both issues enable:
- Authentication bypass
- Unauthorized account takeover
- Administrative access to affected systems
Because of active exploitation in the wild, both vulnerabilities have been flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as known exploited security weaknesses.
A History of Exploiting Public-Facing Vulnerabilities
Storm-1175 has established a reputation for aggressively exploiting newly disclosed vulnerabilities to gain access to enterprise environments.
Over the past several years, the group has been linked to attacks targeting vulnerabilities in:
- Mirth Connect
- ConnectWise ScreenConnect
- JetBrains TeamCity
- Fortinet FortiClient EMS
- Fortra GoAnywhere
In many of these incidents, the attackers used the vulnerabilities as entry points before deploying Medusa ransomware against victim organizations.
Microsoft has repeatedly observed the group moving quickly to exploit the gap between vulnerability disclosure and patch adoption, taking advantage of organizations that delay remediation efforts.
Rapid Lateral Movement and Post-Compromise Activity
Following successful compromise, Storm-1175 employs a range of tools and techniques commonly associated with ransomware operations.
Microsoft observed the group leveraging legitimate remote-access and management software, including:
- AnyDesk
- SimpleHelp
The attackers also use Advanced IP Scanner to map internal networks and identify high-value assets.
For credential theft and privilege escalation, the group has been seen utilizing Mimikatz to dump credentials from the Local Security Authority Subsystem Service (LSASS), enabling access to additional systems and accounts.
Fast-Moving Attacks Increase Risk
One of the most concerning characteristics of Storm-1175 is the speed at which operations unfold.
Researchers noted that the group is capable of progressing from initial access to:
- Internal reconnaissance
- Credential compromise
- Data exfiltration
- Ransomware deployment
within just a few days.
This compressed attack timeline significantly reduces the window available for defenders to detect and contain the intrusion before business-critical systems are encrypted.
Organizations Urged to Patch Immediately
Given the group's demonstrated ability to rapidly weaponize newly disclosed vulnerabilities, organizations using N-able N-central and other internet-facing management platforms should prioritize immediate patching.
Security teams should also:
- Review authentication logs for unusual activity.
- Monitor N-central administrative access.
- Investigate signs of lateral movement.
- Audit remote-management tool usage.
- Search for indicators of credential theft.
- Verify that all affected systems have received the latest security updates.
Conclusion
The appearance of StormEncryptor highlights the continued evolution of Storm-1175's ransomware operations. By shifting away from Medusa and introducing a new ransomware family, the group appears to be expanding its offensive capabilities while continuing its strategy of exploiting newly disclosed vulnerabilities to gain rapid access to target environments. Organizations that rely on exposed management systems and delay security updates remain at heightened risk from this increasingly aggressive threat actor.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
