Find notable cyber news and cases, enriched with sources, timelines, and signals.

StormEncryptor ransomware deployment by Storm-1175

Malware Activity
First reported
Last updated
Happening score
H score 40
2 unique sources, 2 articles

Summary

Hide ▲

Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ransom notes. Microsoft says the China-linked threat actor likely gained access by exploiting CVE-2026-18577 in N-able N-central, then used AnyDesk or SimpleHelp, Advanced IP Scanner, and Mimikatz after compromise. The activity marks a shift from the group's earlier Medusa ransomware use and shows a rapid path from access to data exfiltration and ransomware deployment within a few days. N-able later released hotfix 2026.3 HF1/build 2026.3.1.7 for CVE-2026-18577 and urged immediate installation.

Related Happenings

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
H score49 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool.

About this happening: CVE-2026-18577 is an authentication-bypass vulnerability in N-able N-central that affects hosted and on-premises servers and was used in active exploitation be...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.

Chaos ransomware deployment in STAC4749 intrusions

Malware Activity
H score31 First: 30.07.2026 18:56 Last: 30.07.2026 18:56 Sources 1

About this happening: The Chaos ransomware activity was deployed in at least three intrusions, including one case that reached file encryption in under 17 hours. Attackers used Microsoft...

GodDamn ransomware PoisonX BYOVD activity

Malware Activity
H score14 First: 09.07.2026 13:43 Last: 09.07.2026 13:43 Sources 1

About this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...

Luxury jewelry retailer hit by ransomware attack

Incident
H score45 First: 07.07.2026 16:27 Last: 07.07.2026 16:27 Sources 1

About this happening: A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...

Medusa ransomware post-compromise deployment

Malware Activity
H score48 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...

Timeline

  1. 10.08.2026 20:42 1 articles · 1h ago

    N-able releases hotfix for CVE-2026-18577 in N-central

    Mitigation Patch Update

    N-able released hotfix 2026.3 HF1/build 2026.3.1.7 for CVE-2026-18577 in the N-central remote monitoring and management tool and urged customers to install it immediately.

    Show sources
  2. 10.08.2026 20:42 3 articles · 1h ago

    Storm-1175 deploys StormEncryptor after likely exploiting N-central

    Initial Disclosure

    Microsoft Threat Intelligence says Storm-1175, previously associated with Medusa ransomware, has started using StormEncryptor after likely exploiting CVE-2026-18577 in N-central on targeted systems. The C++ locker appends .encrypted to files, drops !!!README_FIRST!!!.txt ransom notes into scanned directories, and the operator used AnyDesk or SimpleHelp, Advanced IP Scanner, and Mimikatz after gaining access.

    Show sources