Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems

Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems

First seen 10 Aug 2026, 18:07 UTC GbhackersBleepingcomputerScworldNationalinterestwww.blackhillsinfosec.com+4 78.8

Article Content

Browse articles
ThreatCluster

A financially motivated threat actor, Storm-1175, previously linked to Medusa ransomware, has begun deploying a new ransomware strain named StormEncryptor. This campaign was initiated after exploiting an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring tool. The ransomware, written in C++, encrypts files and appends the '.encrypted' extension, dropping a ransom note demanding payment within three days. Storm-1175 is believed to be based in China and has rapidly transitioned from initial access to data exfiltration and ransomware deployment. Microsoft Threat Intelligence has confirmed that this is the first activity observed from Storm-1175 since April 2026. N-able, the vendor of N-central, released a hotfix for the CVE on August 2, 2026, urging immediate installation. Organizations are advised to monitor for signs of Storm-1175 activity and apply security patches promptly.

Key Points: • Storm-1175 has shifted from Medusa ransomware to deploying StormEncryptor. • The ransomware exploits CVE-2026-18577 in N-central, with attacks starting on August 2, 2026. • N-able has released a hotfix for the vulnerability, urging immediate action from system administrators.

Timeline

2026-08-02
StormEncryptor ransomware campaign launched
Storm-1175 began deploying the StormEncryptor ransomware after exploiting CVE-2026-18577 in N-central.
Gbhackers
2026-08-02
Hotfix released for CVE-2026-18577
N-able issued a hotfix for the authentication-bypass vulnerability in N-central, urging immediate installation.
Bleepingcomputer
2026-08-03
CVE-2026-18577 added to CISA KEV
CVE-2026-18577 was added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Bleepingcomputer
2026-08-04
First public PoC for CVE-2026-18577
A proof of concept for the CVE was publicly released, increasing the urgency for patching.
Bleepingcomputer