StormEncryptor ransomware deployment by Storm-1175
Malware Activity
Summary
Hide ▲
Show ▼
Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ransom notes. Microsoft says the China-linked threat actor likely gained access by exploiting CVE-2026-18577 in N-able N-central, then used AnyDesk or SimpleHelp, Advanced IP Scanner, and Mimikatz after compromise. The activity marks a shift from the group's earlier Medusa ransomware use and shows a rapid path from access to data exfiltration and ransomware deployment within a few days. N-able later released hotfix 2026.3 HF1/build 2026.3.1.7 for CVE-2026-18577 and urged immediate installation.
Related Happenings
N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)
Vulnerability
H score49
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
How related:
Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool.
About this happening:
CVE-2026-18577 is an authentication-bypass vulnerability in N-able N-central that affects hosted and on-premises servers and was used in active exploitation be...
N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)
VulnerabilityHow related: Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool.
About this happening: CVE-2026-18577 is an authentication-bypass vulnerability in N-able N-central that affects hosted and on-premises servers and was used in active exploitation be...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.
Chaos ransomware deployment in STAC4749 intrusions
Malware Activity
H score31
First: 30.07.2026 18:56
Last: 30.07.2026 18:56
Sources 1
About this happening:
The Chaos ransomware activity was deployed in at least three intrusions, including one case that reached file encryption in under 17 hours. Attackers used Microsoft...
Chaos ransomware deployment in STAC4749 intrusions
Malware ActivityAbout this happening: The Chaos ransomware activity was deployed in at least three intrusions, including one case that reached file encryption in under 17 hours. Attackers used Microsoft...
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
Luxury jewelry retailer hit by ransomware attack
Incident
H score45
First: 07.07.2026 16:27
Last: 07.07.2026 16:27
Sources 1
About this happening:
A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...
Luxury jewelry retailer hit by ransomware attack
IncidentAbout this happening: A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...
Medusa ransomware post-compromise deployment
Malware Activity
H score48
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...
Medusa ransomware post-compromise deployment
Malware ActivityAbout this happening: Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...
Timeline
-
10.08.2026 20:42 1 articles · 1h ago
N-able releases hotfix for CVE-2026-18577 in N-central
Mitigation Patch UpdateN-able released hotfix 2026.3 HF1/build 2026.3.1.7 for CVE-2026-18577 in the N-central remote monitoring and management tool and urged customers to install it immediately.
Show sources
- New StormEncryptor ransomware used by former Medusa affiliate — www.bleepingcomputer.com — 10.08.2026 20:42
-
10.08.2026 20:42 3 articles · 1h ago
Storm-1175 deploys StormEncryptor after likely exploiting N-central
Initial DisclosureMicrosoft Threat Intelligence says Storm-1175, previously associated with Medusa ransomware, has started using StormEncryptor after likely exploiting CVE-2026-18577 in N-central on targeted systems. The C++ locker appends .encrypted to files, drops !!!README_FIRST!!!.txt ransom notes into scanned directories, and the operator used AnyDesk or SimpleHelp, Advanced IP Scanner, and Mimikatz after gaining access.
Show sources
- New StormEncryptor ransomware used by former Medusa affiliate — www.bleepingcomputer.com — 10.08.2026 20:42
- New StormEncryptor ransomware used by former Medusa affiliate — www.bleepingcomputer.com — 10.08.2026 20:42
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw — thehackernews.com — 10.08.2026 19:38