Ethical Hacking News
A new ransomware strain has replaced Medusa in the latest campaign from China-linked threat actor Storm-1175, further solidifying the group's reputation as a formidable force in the cybersecurity landscape. This development underscores the importance of rapid patching and monitoring to prevent similar attacks from occurring in the future.
Storm-1175 has replaced Medusa ransomware with StormEncryptor, indicating an evolution in their operations. The group is known for its aggressive approach and speed in deploying ransomware, often within days of initial access. Storm-1175 has been linked to high-profile attacks on various organizations, including Microsoft Exchange and JetBrains. The attackers use ZeroDays exploits, such as CVE-2026-18577, to gain quick initial access to systems. The group's tactics emphasize speed, efficiency, and chain attacks, highlighting the importance of rapid patching and monitoring.
Microsoft has recently announced that a new ransomware strain, known as StormEncryptor, has replaced the Medusa ransomware used by the China-linked threat actor Storm-1175. This development marks an evolution in the group's operations and highlights the organization's ability to adapt and improve its tactics, techniques, and procedures (TTPs) in response to emerging vulnerabilities.
The Storm-1175 group is known for its aggressive approach to ransomware attacks, often chaining exploits together to gain deeper access to systems. The attackers target exposed systems and can deploy ransomware within days of initial access. This speed and efficiency make them a highly effective threat actor in the cybersecurity landscape.
Storm-1175 has been linked to various high-profile attacks in recent years, including operations against Microsoft Exchange, Ivanti, ConnectWise, JetBrains, and others. The group's ability to weaponize vulnerabilities quickly, often before organizations apply patches, makes it a significant concern for businesses and organizations worldwide.
In its latest campaign, Storm-1175 has begun using the new ransomware strain called StormEncryptor. This change suggests an evolution in the group's operations and highlights their adaptability as a threat actor. The new ransomware is written in C++ and encrypts files with the .encrypted extension before leaving a README_FIRST.txt file in each scanned directory.
The attackers' use of ZeroDays, particularly CVE-2026-18577 in N-able, has allowed them to gain initial access to systems quickly. This exploit highlights the importance of rapid patching and monitoring to prevent similar attacks from occurring in the future.
The Storm-1175 group's tactics are characterized by their speed and efficiency, often deploying ransomware within days of gaining initial access. The attackers also chain multiple exploits together to achieve deeper access, such as remote code execution. Their use of zero-day flaws before public disclosure demonstrates advanced capabilities.
By focusing on unpatched systems and acting fast, Storm-1175 maximizes its impact and maintains a strong advantage over defenders. This highlights the need for organizations to prioritize patching and monitoring in order to stay ahead of these threats.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Rise-of-Storm-1175-A-New-Player-in-the-Cybersecurity-Threat-Landscape-ehn.shtml
https://securityaffairs.com/197119/malware/storm-1175-replaces-medusa-with-new-stormencryptor-ransomware.html
Published: Thu Aug 13 03:40:15 2026 by llama3.2 3B Q4_K_M