Market
Published Aug 10, 2026Updated Aug 11 Major3
96%
Microsoft Discloses Chinese Hackers Deploying StormEncryptor Ransomware
Microsoft has disclosed that Storm-1175, a China-based financially motivated threat actor, is deploying a new ransomware called StormEncryptor, likely via a vulnerability in N-able N-central software. The group has shifted from previously using Medusa ransomware and exhibits rapid attack timelines from initial access to encryption deployment.
Quick Facts
- Deployment of StormEncryptor ransomware
- Exploitation of CVE-2026-18577 vulnerability in N-able N-central
- Use of remote monitoring tools (AnyDesk, SimpleHelp)
- Network discovery with Advanced IP Scanner
- Credential theft using Mimikatz



Microsoft's Threat Intelligence Team has identified Storm-1175, a financially motivated threat actor based in China, deploying a previously undocumented ransomware strain called StormEncryptor. The malware is written in C++ and encrypts target files while appending the .encrypted file extension, then drops a ransom note titled !!!README_FIRST!!!.txt in each scanned directory. This represents a strategic shift from the group's previous use of Medusa ransomware.
The threat actor is suspected to have exploited CVE-2026-18577, a newly disclosed authentication bypass vulnerability in N-able N-central software, to gain initial access to victim systems. This vulnerability has been identified as a patch bypass for CVE-2026-18556, with both flaws allowing authentication bypass and account takeover on susceptible versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged both vulnerabilities as actively exploited in the wild.
Storm-1175 has a documented history of exploiting software vulnerabilities across multiple platforms. The group has previously leveraged security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208), ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708), JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199), Fortinet FortiClient EMS (CVE-2023-48788), and Fortra GoAnywhere (CVE-2025-10035). The group exploits gaps between vulnerability disclosure and patch deployment to rapidly compromise internet-facing systems.
Post-compromise activities attributed to Storm-1175 include abuse of remote monitoring and management tools such as AnyDesk and SimpleHelp, network discovery using Advanced IP Scanner, and credential theft via LSASS dumping with Mimikatz. The group operates with high velocity, moving from initial access to data exfiltration and ransomware deployment in several days. Microsoft has urged organizations to apply security patches immediately to mitigate the threat.
Why This Matters
Organizations using N-able N-central or similar internet-facing software face measurable operational risk: exploitation of CVE-2026-18577 enables ransomware deployment within days of initial compromise. Affected sectors include IT service providers, healthcare, and finance. Patch deployment timelines and credential management protocols directly determine exposure window; CISA has flagged both CVE-2026-18577 and CVE-2026-18556 as actively exploited in production environments.
Sources
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawthe_hacker_newsMediaAug 10, 2026
- Petaka Baru Datang dari China, Satu Dunia Terancam Jadi KorbanCNBC IndonesiaMediaAug 11, 2026
- Peretas Internasional Serang Sistem Perusahaan dan Tiket Konser GlobalAchmad Nur HidayatMediaAug 11, 2026