Connect with us

Security

Unleashing Chaos: China-Linked Hackers Strike with StormEncryptor Ransomware Through N-central Vulnerability

Published

on

China-Linked Threat Actor Storm-1175 Unleashes New Ransomware Strain StormEncryptor

Recent reports from Microsoft reveal that Storm-1175, a threat actor associated with China, has introduced a new strain of ransomware known as StormEncryptor, signaling a departure from their usual Medusa ransomware tactics.

Written in C++, StormEncryptor encrypts files and appends the extension .encrypted to the affected files, accompanied by a ransom note named !!!README_FIRST!!!.txt in each directory.

While the specific vulnerability exploited by Storm-1175 remains undisclosed, Microsoft suggests it may involve CVE-2026-18577, a newly identified security flaw in N-able N‑central, used for initial access.

This vulnerability is believed to be a patch bypass for CVE-2026-18556, both enabling authentication bypass and account takeover in vulnerable versions, as highlighted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Storm-1175, recognized for leveraging vulnerabilities in various platforms like Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS, has now turned to exploiting N-able N‑central and other tools for malicious activities.

Microsoft’s analysis in October 2025 linked Storm-1175 to the exploitation of a critical vulnerability in Fortra GoAnywhere to deploy Medusa ransomware, showcasing the threat actor’s evolving tactics.

Utilizing a mix of zero-day and N-day vulnerabilities, Storm-1175 swiftly infiltrates internet-facing systems, taking advantage of the time gap between vulnerability disclosure and patch implementation.

Post-compromise activities by Storm-1175 involve exploiting remote monitoring tools like AnyDesk and SimpleHelp, Advanced IP Scanner for reconnaissance, and Mimikatz for LSASS dumping, showcasing a sophisticated attack strategy.

Storm-1175’s rapid progression from initial access to data theft and ransomware deployment underscores the urgency for organizations to promptly apply security patches to mitigate potential risks.

See also  Cybersecurity Alert: PAN-OS RCE Exploit, Mythos cURL Vulnerability, AI Tokenizer Attacks, and More Threats Detected

Trending