
Microsoft has disclosed that Storm-1175, a China-linked financially motivated threat actor with a history of exploiting enterprise software vulnerabilities, has switched from Medusa ransomware to a newly documented strain called StormEncryptor. The new ransomware is written in C++, appends the .encrypted extension to files it locks, and drops a ransom note named !!!README_FIRST!!!.txt in every directory it processes.
The group’s suspected entry point is CVE-2026-18577, an authentication-bypass flaw in N-able N-central that serves as a patch bypass for an earlier vulnerability, CVE-2026-18556. Both allow authentication bypass and account takeover. CISA has designated both as actively exploited. Once inside, Storm-1175 follows a familiar playbook: remote management via AnyDesk or SimpleHelp, network mapping with Advanced IP Scanner, and credential theft from LSASS memory using Mimikatz. The group moves quickly — data exfiltration and ransomware deployment typically happen within days of initial access, leaving little time to detect and contain the intrusion.
Storm-1175 has previously leveraged vulnerabilities in Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, Fortinet FortiClient EMS, and Fortra GoAnywhere to deploy Medusa ransomware. The shift to a custom strain suggests the group is maturing its toolkit and working to evade detection logic tuned for Medusa.
How to check if you’re affected
Affected products include N-able N-central installations running versions vulnerable to CVE-2026-18577 and CVE-2026-18556. Apply N-able’s patches for both CVEs immediately — CISA’s designation as actively exploited means the window between disclosure and exploitation in your environment may already be closed. Additionally, review remote-management tool installations (AnyDesk, SimpleHelp) for any endpoints where they were not deliberately installed, and check authentication logs on N-central for unusual account activity.
