Former Medusa Affiliate Debuts New Ransomware
Microsoft tracks Storm-1175's shift to StormEncryptor, following exploitation of an N-central flaw.
Microsoft Threat Intelligence has identified a new ransomware strain called StormEncryptor, deployed by a financially motivated threat actor previously tied to the Medusa ransomware operation. The activity, tracked as Storm-1175, marks the actor's first observed campaign since April 2026 and signals a departure from its known use of Medusa ransomware.
Storm-1175's Tactics Evolve
According to Microsoft, Storm-1175 is believed to operate from China and has a history of targeting vulnerabilities across multiple platforms, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity. The recent attacks involving StormEncryptor were likely preceded by exploitation of an authentication-bypass vulnerability, tracked as CVE-2026-18577, in the N-central remote monitoring and management (RMM) tool.
Microsoft notes that Storm-1175's use of StormEncryptor represents a notable shift, as the actor had previously been associated with Medusa ransomware. The exact motivations behind this change are not detailed, but the move underscores the evolving tactics of financially driven threat actors.
How StormEncryptor Works
StormEncryptor is a C++ based malware that appends encrypted files with the ".encrypted" extension and drops a ransom note named '!!!README_FIRST!!!.txt' into every scanned directory. The ransom note instructs victims to contact the attacker within three days to negotiate a payment, threatening to leak stolen data if demands are not met.
Microsoft's analysis indicates the malware is designed to encrypt files efficiently, targeting systems after gaining initial access. The use of a distinct file extension and ransom note suggests a streamlined ransomware operation, potentially optimized for speed and impact.
Rapid Post-Exploitation Activity
Microsoft reports that Storm-1175 moves quickly after compromising a network, often completing data exfiltration and ransomware deployment within a few days. The actor employed legitimate remote management tools such as AnyDesk or SimpleHelp, used Advanced IP Scanner for network discovery, and leveraged Mimikatz to dump credentials from the Local Security Authority Subsystem Service (LSASS) process.
This combination of tools allows the attacker to move laterally, escalate privileges, and exfiltrate data before deploying the locker. Microsoft warns that the speed of these operations makes timely detection and response critical.
N-able Addresses the Vulnerability
N-able, the vendor of N-central, released a hotfix (2026.3 HF1/build 2026.3.1.7) on August 2 to address CVE-2026-18577, urging customers to install the patch immediately. The company also previously recommended administrators check for signs of compromise, including an svchost.exe file in the Documents folders of users' devices, a registered service named Cloudflared, and inbound connections from IP addresses listed in their advisory.
These indicators can help organizations detect whether the vulnerability has been exploited before applying the patch. N-able emphasized the importance of patching as the primary mitigation.
Microsoft's Warning to Administrators
Microsoft explicitly warned that this threat actor is known to rapidly move from initial access to data exfiltration and ransomware deployment, often within a few days. The company urged organizations to monitor for Storm-1175 activity and apply security patches as soon as possible.
The advisory stresses that self-hosted N-central servers are at particular risk, and administrators should prioritize securing these systems. Microsoft's guidance includes reviewing logs for the specific indicators provided by N-able and implementing robust monitoring for the tools and tactics associated with Storm-1175.
Implications for Defenders
The emergence of StormEncryptor highlights the persistent threat posed by financially motivated actors who adapt their tooling. For organizations using RMM tools like N-central, the lesson is clear: unpatched systems provide a direct pathway for ransomware attacks. Administrators should treat any unpatched RMM system as a high-priority risk and ensure that security patches are applied promptly.
Furthermore, the shift from Medusa to a new ransomware variant suggests that threat actors may be willing to change their malware to avoid detection or improve effectiveness. This could mean that other former Medusa affiliates might follow suit, adopting new ransomware strains to evade existing defenses. For defenders, the key takeaway is to stay vigilant, monitor for indicators of compromise, and maintain robust patch management practices.
Sources
- BleepingComputer Original source
Continue Reading
Ceva Breach Reverberates Through Client Ecosystem
A Ceva Logistics data breach affecting European clients shows how supply chain attacks ripple outward.
Storm-1175 Debuts New Ransomware
Microsoft says China-linked Storm-1175 shifts from Medusa to the new StormEncryptor ransomware, likely via N-central flaw CVE-2026-18577.
Kimsuky's Offline AI Stack Signals Smarter Phishing
North Korea's Kimsuky group is building offline AI tools to automate malware and phishing, a Genians report says.