Bleepingcomputer
Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A financially motivated threat actor, Storm-1175, has launched a new ransomware strain called StormEncryptor, previously linked to Medusa ransomware. The attacks began on August 2, 2026, exploiting an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring tool. This marks Storm-1175's first activity since April 2026, indicating a shift in their tactics. StormEncryptor encrypts files with the '.encrypted' extension and threatens data leakage if ransoms are not paid within three days. The threat actor utilizes tools like AnyDesk and Mimikatz for remote management and credential dumping. Microsoft warns that the actor moves quickly from initial access to data exfiltration and ransomware deployment. Organizations using N-central are urged to apply the hotfix released on August 2, 2026, to mitigate the vulnerability. Security teams are advised to monitor for signs of Storm-1175 activity.
Key Points: • Storm-1175 has shifted from Medusa ransomware to a new strain called StormEncryptor. • The attacks exploit CVE-2026-18577, an authentication-bypass vulnerability in N-central. • Victims are given three days to negotiate a ransom before data is leaked online.