StormEncryptor Ransomware Deployed by Former Medusa Affiliate
TL;DR. A threat actor previously linked to Medusa ransomware now uses StormEncryptor, targeting systems via N-central RMM tool vulnerabilities. - Microsoft identifies the actor as Storm-1175, noting rapid data exfiltration and ransomware deployment. - StormEncryptor, a C++ malware, encrypts files and drops ransom notes, demanding payment in three days. - The attacker leverages tools like AnyDesk and Mimikatz for network management and credential dumping. - N-able released a hotfix for the CVE-2026-18577 vulnerability in N-central RMM.
- A former Medusa ransomware affiliate is deploying a new strain called StormEncryptor.
- Microsoft Threat Intelligence tracks this actor as Storm-1175, citing China as its likely base.
- Initial access is gained through an authentication-bypass vulnerability (CVE-2026-18577) in N-central RMM.
- Storm-1175 moves quickly from compromise to data exfiltration and ransomware deployment.
- StormEncryptor is C++ malware that appends '.encrypted' to files and drops a ransom note.
Sources
- New StormEncryptor ransomware used by former Medusa affiliate — bleepingcomputer.com
- thehackernews.com — thehackernews.com