Microsoft has revealed that a financially driven threat group, Storm-1175, associated with China, has introduced a new ransomware strain, StormEncryptor. This development indicates a strategic shift from their earlier use of Medusa ransomware.
New Ransomware Strategy
StormEncryptor, crafted in C++, alters file extensions to .encrypted and leaves a ransom note titled !!!README_FIRST!!!.txt in each directory it scans. This marks a departure from the group’s previous ransomware tactics.
While the precise vulnerability utilized by Storm-1175 in this operation remains unidentified, Microsoft suggests that it likely involves exploiting the newly reported CVE-2026-18577 flaw in N-able N-central, potentially enabling initial access to systems.
Exploiting Security Flaws
The CVE-2026-18577 vulnerability is considered a patch bypass for CVE-2026-18556, both of which facilitate authentication bypass and account takeover in vulnerable systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged these vulnerabilities as actively targeted.
Storm-1175, known for leveraging Medusa ransomware, has a history of exploiting security loopholes in multiple technologies, including Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS, showcasing their adeptness at capitalizing on both zero-day and N-day vulnerabilities.
Advanced Attack Tactics
Microsoft’s October 2025 analysis linked Storm-1175 to exploiting a critical vulnerability in Fortra GoAnywhere, facilitating Medusa ransomware deployment. The group is known for executing rapid attacks by exploiting the window between vulnerability disclosure and patch adoption.
In their latest activities, Storm-1175’s post-compromise strategies include abusing remote monitoring tools like AnyDesk and SimpleHelp, utilizing Advanced IP Scanner for network discovery, and deploying Mimikatz for credential dumping from LSASS.
Rapid Deployment and Recommendations
Storm-1175 has demonstrated swift transitions from initial system access to data exfiltration and ransomware deployment, often within a few days. This rapid escalation highlights the urgent need for organizations to implement security patches promptly.
Organizations are advised to stay vigilant and apply patches immediately to mitigate the risk of ransomware attacks and safeguard their systems from such sophisticated threats.
