China-linked Storm-1175 deploys new StormEncryptor ransomware after exploiting an N-able N-central bug
Microsoft $MSFT says China-linked group Storm-1175 has shifted from Medusa to a new ransomware strain, StormEncryptor, likely gaining initial access through an authentication-bypass flaw in N-able's $NABL N-central software, patched August 2. Per BleepingComputer and The Hacker N
Microsoft $MSFT Threat Intelligence says the China-linked, financially motivated group Storm-1175 has deployed a new ransomware strain called StormEncryptor, marking a shift away from its previous use of Medusa ransomware and its first observed activity since April 2026. StormEncryptor is written in C++, appends a .encrypted extension to locked files, and drops a ransom note named !!!README_FIRST!!!.txt in every scanned directory, giving victims three days to respond before stolen data is leaked. Microsoft assesses the attackers likely gained initial access by exploiting CVE-2026-18577, an authentication-bypass flaw in N-able's $NABL N-central remote monitoring and management tool, before using AnyDesk, SimpleHelp, Advanced IP Scanner and Mimikatz to move through victim networks. N-able shipped a hotfix (build 2026.3.1.7) on August 2, 2026. Sources: Microsoft Threat Intelligence, BleepingComputer, The Hacker News. Visuals and voiceover are AI-generated.