StormEncryptor Ransomware Deployed by Former Medusa Affiliate

TL;DR. A threat actor previously linked to Medusa ransomware now uses StormEncryptor, targeting systems via N-central RMM tool vulnerabilities. - Microsoft identifies the actor as Storm-1175, noting rapid data exfiltration and ransomware deployment. - StormEncryptor, a C++ malware, encrypts files and drops ransom notes, demanding payment in three days. - The attacker leverages tools like AnyDesk and Mimikatz for network management and credential dumping. - N-able released a hotfix for the CVE-2026-18577 vulnerability in N-central RMM.

Sources

Back to QLANKR News