Connect with us

Security

Unleashing Chaos: China-Linked Hackers Strike with StormEncryptor Ransomware Through N-central Vulnerability

Published

on

China-Linked Threat Actor Storm-1175 Unleashes New Ransomware Strain StormEncryptor

Recent reports from Microsoft reveal that Storm-1175, a threat actor associated with China, has introduced a new strain of ransomware known as StormEncryptor, signaling a departure from their usual Medusa ransomware tactics.

Written in C++, StormEncryptor encrypts files and appends the extension .encrypted to the affected files, accompanied by a ransom note named !!!README_FIRST!!!.txt in each directory.

While the specific vulnerability exploited by Storm-1175 remains undisclosed, Microsoft suggests it may involve CVE-2026-18577, a newly identified security flaw in N-able N‑central, used for initial access.

This vulnerability is believed to be a patch bypass for CVE-2026-18556, both enabling authentication bypass and account takeover in vulnerable versions, as highlighted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Storm-1175, recognized for leveraging vulnerabilities in various platforms like Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS, has now turned to exploiting N-able N‑central and other tools for malicious activities.

Microsoft’s analysis in October 2025 linked Storm-1175 to the exploitation of a critical vulnerability in Fortra GoAnywhere to deploy Medusa ransomware, showcasing the threat actor’s evolving tactics.

Utilizing a mix of zero-day and N-day vulnerabilities, Storm-1175 swiftly infiltrates internet-facing systems, taking advantage of the time gap between vulnerability disclosure and patch implementation.

Post-compromise activities by Storm-1175 involve exploiting remote monitoring tools like AnyDesk and SimpleHelp, Advanced IP Scanner for reconnaissance, and Mimikatz for LSASS dumping, showcasing a sophisticated attack strategy.

Storm-1175’s rapid progression from initial access to data theft and ransomware deployment underscores the urgency for organizations to promptly apply security patches to mitigate potential risks.

See also  Discord Data Breach Exposes User Info and Scanned Photo IDs: Customer Service Incident Sparks Concern

Trending