China-Linked Threat Actor Storm-1175 Unleashes New Ransomware Strain StormEncryptor
Recent reports from Microsoft reveal that Storm-1175, a threat actor associated with China, has introduced a new strain of ransomware known as StormEncryptor, signaling a departure from their usual Medusa ransomware tactics.
Written in C++, StormEncryptor encrypts files and appends the extension .encrypted to the affected files, accompanied by a ransom note named !!!README_FIRST!!!.txt in each directory.
While the specific vulnerability exploited by Storm-1175 remains undisclosed, Microsoft suggests it may involve CVE-2026-18577, a newly identified security flaw in N-able N‑central, used for initial access.
This vulnerability is believed to be a patch bypass for CVE-2026-18556, both enabling authentication bypass and account takeover in vulnerable versions, as highlighted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Storm-1175, recognized for leveraging vulnerabilities in various platforms like Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS, has now turned to exploiting N-able N‑central and other tools for malicious activities.
Microsoft’s analysis in October 2025 linked Storm-1175 to the exploitation of a critical vulnerability in Fortra GoAnywhere to deploy Medusa ransomware, showcasing the threat actor’s evolving tactics.
Utilizing a mix of zero-day and N-day vulnerabilities, Storm-1175 swiftly infiltrates internet-facing systems, taking advantage of the time gap between vulnerability disclosure and patch implementation.
Post-compromise activities by Storm-1175 involve exploiting remote monitoring tools like AnyDesk and SimpleHelp, Advanced IP Scanner for reconnaissance, and Mimikatz for LSASS dumping, showcasing a sophisticated attack strategy.
Storm-1175’s rapid progression from initial access to data theft and ransomware deployment underscores the urgency for organizations to promptly apply security patches to mitigate potential risks.

