Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems

Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems

First seen 10 Aug 2026, 18:07 UTC GbhackersBleepingcomputerwiz.iostatus.n-able.com 91% similarity 74.8

Article Content

Browse articles
ThreatCluster

A financially motivated threat actor, Storm-1175, has launched a new ransomware strain called StormEncryptor, previously linked to Medusa ransomware. The attacks began on August 2, 2026, exploiting an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring tool. This marks Storm-1175's first activity since April 2026, indicating a shift in their tactics. StormEncryptor encrypts files with the '.encrypted' extension and threatens data leakage if ransoms are not paid within three days. The threat actor utilizes tools like AnyDesk and Mimikatz for remote management and credential dumping. Microsoft warns that the actor moves quickly from initial access to data exfiltration and ransomware deployment. Organizations using N-central are urged to apply the hotfix released on August 2, 2026, to mitigate the vulnerability. Security teams are advised to monitor for signs of Storm-1175 activity.

Key Points: • Storm-1175 has shifted from Medusa ransomware to a new strain called StormEncryptor. • The attacks exploit CVE-2026-18577, an authentication-bypass vulnerability in N-central. • Victims are given three days to negotiate a ransom before data is leaked online.

ThreatCluster AI How this analysis works

Timeline

2026-08-02
CVE-2026-18577 published
An authentication-bypass vulnerability in N-central was disclosed, allowing exploitation by threat actors.
BleepingComputer
2026-08-02
StormEncryptor ransomware attacks began
Storm-1175 started deploying StormEncryptor ransomware, marking its first activity since April 2026.
Gbhackers
2026-08-03
CVE-2026-18577 added to CISA KEV
CISA recognized the vulnerability as actively exploited, prompting urgent attention from organizations.
BleepingComputer
2026-08-04
First public PoC for CVE-2026-18577
A proof of concept for the vulnerability was released, increasing the risk of exploitation.
BleepingComputer

Community

Browse all →