Ethical Hacking News
The use of StormEncryptor ransomware marks a significant shift in the tactics employed by China-linked hackers known as Storm-1175. This new variant exploits a security flaw in N-able N‑central, raising concerns over vulnerabilities that could be exploited to gain initial access. As cybersecurity threats continue to evolve, it is essential to stay informed and take proactive measures to protect against such threats.
The StormEncryptor ransomware is a financially motivated tool wielded by a China-linked hacker group known as Storm-1175. The malware appends a file extension of .encrypted to files it encrypts and drops a ransom note upon encryption. The exploitation of CVE-2026-18577 in N-able N‑central is the primary vector for Storm-1175's attack. Storm-1175 has been linked to exploiting critical vulnerabilities, including Fortra GoAnywhere and Fortinet FortiClient EMS. The group uses post-compromise behavior, abusing remote monitoring and management tools, advanced IP scanners, and LSASS dumping using Mimikatz. The involvement of Storm-1175 in deploying the StormEncryptor ransomware signifies a new direction in its operations, with more aggressive tactics being employed.
The cybersecurity landscape has been plagued by an increasing number of threats, each more sinister than the last. One such threat that has recently come to light is the StormEncryptor ransomware, a financially motivated tool wielded by a China-linked hacker group known as Storm-1175. This article will delve into the world of cybercrime, exploring the origins and tactics of this new ransomware strain, its connections to previous Medusa ransomware attacks, and the potential vulnerabilities that could be exploited by this group.
StormEncryptor is a previously undocumented ransomware strain written in C++, designed to append a file extension of .encrypted to files it encrypts. Upon encryption, the malware drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory. This new variant marks a shift from Storm-1175's previous use of Medusa ransomware, a tool previously employed by this group in exploits targeting various Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS vulnerabilities.
The exploitation of CVE-2026-18577, a newly disclosed security flaw in N-able N‑central, is believed to be the primary vector for Storm-1175's attack. This vulnerability is assessed as a patch bypass that enables authentication bypass and account takeover in susceptible versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already flagged this vulnerability as actively exploited in the wild.
Storm-1175's exploits are not new to cybersecurity professionals. In October 2025, Microsoft attributed the group to exploiting a critical security vulnerability impacting Fortra GoAnywhere, facilitating the deployment of Medusa ransomware. The group weaponizes zero-days and N-day vulnerabilities to carry out high-velocity attacks, breaching susceptible internet-facing systems by capitalizing on the time gap between vulnerability disclosure and patch adoption.
The latest activity from Storm-1175 involves post-compromise behavior that includes abuse of remote monitoring and management tools such as AnyDesk or SimpleHelp, advanced IP scanners like Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz. This group rapidly moves from initial access to data exfiltration and ransomware deployment, primarily within a few days, necessitating prompt patching by customers.
The involvement of Storm-1175 in deploying the StormEncryptor ransomware signifies a new direction in its operations. By shifting away from Medusa ransomware and adopting this more aggressive approach, the group is likely attempting to stay one step ahead of cybersecurity professionals. The use of highly sophisticated tactics such as exploiting vulnerabilities in N-able N‑central underscores the evolving nature of cyber threats.
In conclusion, the emergence of StormEncryptor ransomware as a new tool wielded by China-linked hackers raises significant concerns for individuals and organizations alike. As cybersecurity landscapes continue to evolve, it is imperative that individuals and businesses remain vigilant, applying patches and taking proactive measures to protect themselves against such threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Looming-Threat-StormEncryptor-Ransomware-and-its-Ties-to-China-ehn.shtml
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
https://www.linkedin.com/posts/cybercureme_china-linked-hackers-deploy-new-stormencryptor-activity-7492641567099260928-9U0D
https://nvd.nist.gov/vuln/detail/CVE-2026-18577
https://www.cvedetails.com/cve/CVE-2026-18577/
https://cyberpress.org/storm-1175-deploys-new-stormencryptor-ransomware/
Published: Mon Aug 10 14:56:14 2026 by llama3.2 3B Q4_K_M