Microsoft has disclosed a new ransomware strain called StormEncryptor ransomware, deployed by the China-linked threat actor Storm-1175. According to the company, the group is financially motivated and has historically used other ransomware families—most notably Medusa. This shift suggests the attackers continue to refine their tooling while targeting internet-facing environments.
In Microsoft’s reporting, StormEncryptor is described as a C++-written ransomware that encrypts files and leaves a distinct ransom note. While the precise vulnerability used to reach targeted networks was not confirmed, Microsoft believes the campaign likely involved a flaw in N-able N-central, which has been flagged by U.S. authorities as actively exploited.
What Microsoft says about StormEncryptor ransomware
StormEncryptor stands out in Microsoft’s analysis due to its behavior and file artifacts. Microsoft notes that the malware appends the extension .encrypted to files it encrypts. In addition, it drops a ransom note named !!!README_FIRST!!!.txt into every scanned directory, a pattern defenders can use when validating incident indicators.
Microsoft also highlights that StormEncryptor represents a change in the attacker’s ransomware usage. Instead of relying on Medusa as in prior activity, this campaign uses a previously undocumented strain.
Likely entry via N-able N-central vulnerability
Although Microsoft did not publicly confirm the exact exploited weakness, it assessed that initial access likely involved CVE-2026-18577, a newly disclosed security flaw in N-able N-central. This matters because initial access often determines how quickly an organization can detect intrusion and contain the threat.
Microsoft further explains that the vulnerability is assessed to be related to CVE-2026-18556. Both issues can enable an authentication bypass and account takeover in susceptible versions.
In line with this risk, the vulnerabilities have been flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited in the wild. When a flaw is under active exploitation, delays in patching can translate into faster ransomware deployment for attackers.
How Storm-1175 typically operates
Storm-1175 is the label Microsoft assigns to a threat actor linked to China. The company connects the group to earlier ransomware campaigns in which it exploited multiple third-party vulnerabilities to gain footholds in targeted environments.
Microsoft’s historical association includes exploitation of issues in products such as Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS. In an additional Microsoft analysis published in October 2025, Storm-1175 was also attributed to activity involving Fortra GoAnywhere (CVE-2025-10035) to support deployment of Medusa ransomware.
Across these incidents, Microsoft describes a consistent theme: the attackers weaponize a combination of zero-day and N-day vulnerabilities and then move quickly to compromise systems exposed to the internet. Their approach also emphasizes the time window between vulnerability disclosure and patch adoption.
Post-compromise actions reported by Microsoft
Once Storm-1175 gains access, Microsoft indicates the group’s behavior focuses on establishing control, discovering hosts, and progressing toward data theft and encryption. In this new activity, the company notes several operational steps defenders should recognize.
- Remote monitoring and management abuse: AnyDesk or SimpleHelp.
- Network and system discovery: Advanced IP Scanner.
- Credential and memory access attempts: LSASS dumping using Mimikatz.
Microsoft also reports that the threat actor can move from initial access to exfiltration and ransomware deployment rapidly—often within a few days. That speed increases the importance of early detection and immediate remediation after any suspected exposure.
Why patching quickly is critical
StormEncryptor ransomware is a reminder that ransomware campaigns often follow a predictable pattern: compromise first, then privilege escalation and discovery, followed by exfiltration and encryption. If defenders patch only after an incident is confirmed, attackers may already have completed the steps needed to deploy ransomware.
Because Microsoft believes the campaign likely involved an N-central authentication bypass pathway—and because related vulnerabilities have been flagged as actively exploited—organizations using N-able N-central should treat this as an urgent patching and review event.
Even if your environment is not currently suspected, the safest approach is to apply security updates promptly and verify that external-facing services are hardened and monitored. If you maintain logs from remote management tools and authentication events, review them for anomalous access patterns around the time of known exploitation attempts.
What defenders can do right now
While this disclosure does not provide a complete technical playbook for every stage, the behavior Microsoft describes offers practical actions. Consider the following defensive priorities:
- Update N-able N-central to the fixed versions for the relevant vulnerabilities (including CVE-2026-18577 and the related issue Microsoft discussed).
- Hunt for ransomware indicators, such as files renamed with .encrypted and the presence of !!!README_FIRST!!!.txt.
- Monitor remote access and admin tooling associated with AnyDesk and SimpleHelp, especially from unusual hosts or user accounts.
- Review discovery activity that aligns with Advanced IP Scanner usage (for example, repeated scanning or abnormal network traffic).
- Look for signs consistent with LSASS dumping and credential access attempts.
Most importantly, treat “active exploitation” as a signal that the threat may already be attempting intrusions across the broader internet—not just targeting a single organization.
Takeaway: a new ransomware strain, same fast playbook
StormEncryptor ransomware shows that Storm-1175 continues to adapt its ransomware payloads while leaning on effective initial access strategies. Microsoft’s reporting links the campaign to likely exploitation of an N-central vulnerability and describes post-compromise activity that accelerates discovery and progression to encryption.
If you operate systems exposed to the internet—especially remote monitoring and management products—this disclosure reinforces a clear message: prioritize patching, verify exposure, and strengthen monitoring so you can detect early compromise before ransomware deployment becomes inevitable.
Source: https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
