HomeSecurityStormEncryptor ransomware changes tactics after Medusa

StormEncryptor ransomware changes tactics after Medusa

The StormEncryptor ransomware marks a new phase for the Storm-1175 agent, which was previously linked to Operation Medusa. Microsoft is now seeing a different cryptographer in attacks that likely originate from the critical CVE-2026-18577 in N-able's N-central.

The new activity reveals a familiar, but remarkably rapid attack chain. After initial access, the attackers move through the network, collecting credentials, stealing files, and deploying the malware within a matter of days.

See also: N-central CVE-2026-18577: New N-able hotfix for administrators

StormEncryptor ransomware and the change in tactics

Storm-1175 is a financially motivated threat actor that Microsoft believes operates from China. It previously used the Medusa ransomware, but the development of StormEncryptor is the first such activity detected since April 2026 and indicates a shift away from the previous ecosystem.

According to BleepingComputer, the new malware is written in C++ and encrypts files, adding the extension .encrypted. In each directory scanned, it creates the note !!!README_FIRST!!!.txt, while the perpetrators give victims three days to contact and negotiate a ransom.

The threat is not limited to encryption. The extortion is also based on data theft, with the threat of making files public if payment is not made. So far, no specific victims or industries affected by StormEncryptor have been announced, so organizations should treat the campaign as a broader risk and not as an isolated incident.

StormEncryptor ransomware attacks exploit highly sensitive management points. An RMM server is not just another application on the network, as it can execute commands on multiple computers and provide visibility into the entire infrastructure. Therefore, a compromised administrator account can turn an initial security breach into a widespread outage.

The absence of named victims does not mean that the risk is theoretical. Organizations using N-central should review logs from the past few weeks, confirm which accounts had administrative privileges, and isolate any unexpected remote access tools before beginning the recovery process.

StormEncryptor ransomware on corporate network

CVE-2026-18577 paves the way

The recent attacks likely stem from CVE-2026-18577, an authentication bypass vulnerability in N-central RMM. The issue primarily affects locally hosted servers and could give an attacker the initial push to access environments that manage multiple devices.

Once inside, Storm-1175 used the remote administration tools AnyDesk and SimpleHelp, as well as Advanced IP Scanner to scan systems. Mimikatz was leveraged to extract credentials from the LSASS process. This sequence allows the attacker to understand the network and select the most useful systems before deploying the cryptographer.

Microsoft Threat Intelligence describes Storm-1175 as an agent that moves at high speed from initial breach to data theft and ransomware deployment. The new campaign reinforces the need for continuous monitoring of exposed services, especially when an RMM tool has access to a large portion of the infrastructure.

See also: N-central: Critical vulnerability in CISA's KEV after breaches

CVE-2026-18577 in N-central RMM

What should administrators do?

N-able has released the patch version 2026.3.1.7, known as 2026.3 HF1, and recommends immediate upgrade of local N-central installations. Hosted installations are upgraded automatically, but administrators must verify that the process is complete and that there is no old server in the environment.

The official N-able advisory states that defense teams should check users' Documents folders for a file named svchost.exe, as well as for a registered Cloudflared. It is also useful to check firewalls for incoming connections from the addresses 173[.]249[.]252[.]200, 87[.]249[.]138[.]34, 37[.]19[.]210[.]32 and 68[.]235[.]46[.]214.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, it is necessary to restrict access to remote management tools, support multi-factor authentication, and record administrator actions. The SecNews technical team suggests considering any sudden installation of RMM software, any unexplained export of credentials, and any attempt to access backups as suspicious.

See also: CISA: Langflow RCE, Tomcat and N-central actively exploited

StormEncryptor ransomware protection

The StormEncryptor ransomware shows that ransomware groups can quickly change tools without abandoning the same practices of initial access and lateral movement. Early patching, monitoring for signs of compromise, and strict isolation of RMM services remain the most immediate defensive steps.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS