HomeMalware & ThreatsChina-Linked Hackers Unleash New StormEncryptor Ransomware, Potentially Exploiting N-central Vulnerability

China-Linked Hackers Unleash New StormEncryptor Ransomware, Potentially Exploiting N-central Vulnerability

Published on

spot_img

Storm-1175: New Ransomware Threat Emerges from China

Recent revelations from Microsoft have exposed a sophisticated ransomware threat known as Storm-1175, which has emerged from a financially motivated group linked to China. This entity has recently introduced a new type of ransomware called StormEncryptor, signifying a strategic pivot from their earlier deployment of the Medusa ransomware variant. This transition illustrates the evolving tactics employed by cybercriminals in today’s digital landscape.

StormEncryptor, crafted in C++, operates by appending the file extension ".encrypted" to any files it encrypts. In a systematic approach to instill panic among victims, it also generates a ransom note titled !!!README_FIRST!!!.txt, which is distributed to all directories scanned during the attack. This note serves as both a communication tool and a means to exert pressure on victims to fulfill the ransom demands swiftly.

While Microsoft has yet to pinpoint the exact vulnerabilities exploited during this campaign, indications suggest that the group may be leveraging CVE-2026-18577, a newly unearthed security flaw within N-able N‑central. This vulnerability presumably enables the attackers to gain initial entry into targeted systems. Additionally, it has been characterized as a patch bypass for CVE-2026-18556, both of which permit authentication bypass and account takeovers in affected versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already classified these vulnerabilities as being actively exploited in the wild, signaling an urgent need for vigilance in cybersecurity measures.

Storm-1175 has a notorious history of deploying the Medusa ransomware after exploiting various security weaknesses present in platforms like Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS. This group has effectively capitalized on vulnerabilities, including CVE-2023-37679, CVE-2023-43208, CVE-2024-1709, CVE-2024-27198, and CVE-2023-48788, among others, showcasing a comprehensive understanding and exploitation capability within prevalent software systems.

In a prior analysis published in October 2025, Microsoft linked Storm-1175’s activities to the exploitation of a critical vulnerability affecting Fortra GoAnywhere (CVE-2025-10035), which enabled them to further deploy the Medusa ransomware. By using a mixture of zero-day and N-day vulnerabilities, this group—recognized for its aggressive tactics—conducts rapid-fire attacks targeting vulnerable, internet-facing systems. They specifically aim to weaponize the gap that exists between the disclosure of a security vulnerability and the subsequent adoption of patches, allowing them to infiltrate networks with relative ease.

In their latest activities, the operational methods of Storm-1175 have become more complex. Apart from exploiting identifiable vulnerabilities, they have also been seen utilizing remote monitoring and management tools like AnyDesk and SimpleHelp for control over infected systems. Furthermore, they employ Advanced IP Scanner for device discovery and leverage tools like Mimikatz to extract credentials, notably focusing on LSASS (Local Security Authority Subsystem Service) dumping.

This rapid transition from gaining initial access to executing data exfiltration and deploying ransomware is alarming. Microsoft reports that this entire process can occur within just a few days, reaffirming the necessity for organizations to apply security updates and patches without delay. The swift movements of Storm-1175 underscore the urgency for all sectors to prioritize cybersecurity, particularly in light of the increasing sophistication and frequency of ransomware attacks.

Overall, the emergence of StormEncryptor signifies not only a change in tactics for Storm-1175 but an augmented threat landscape for organizations globally. With the cyber environment growing more perilous, the stakes are high for both individuals and businesses to adopt rigorous cybersecurity measures. Failing to do so could have dire financial and operational repercussions, as demonstrated by the patterns of cyberattacks explored through this newly surfaced threat.

Source link

Latest articles

China-Linked Hackers Exploit N-able Vulnerability in Ransomware Attacks

Microsoft Warns of Ransomware Attacks by China-Linked Storm-1175 Group In a recent security alert, Microsoft...

Least Privilege at Scale with Microsoft Intune: The Simplicity of Removing Local Admin Rights

Understanding Endpoint Privilege Management: The Path to Effective Least Privilege The challenge of managing local...

CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild

Critical Command Injection Vulnerability in Progress LoadMaster Identified by CISA The U.S. Cybersecurity and Infrastructure...

US Sanctions Iranian $6 Billion Crypto Exchange Shelbit

U.S. Sanctions Iranian Firm for Role in Illicit Cryptocurrency Operations In a significant move reflecting...

More like this

China-Linked Hackers Exploit N-able Vulnerability in Ransomware Attacks

Microsoft Warns of Ransomware Attacks by China-Linked Storm-1175 Group In a recent security alert, Microsoft...

Least Privilege at Scale with Microsoft Intune: The Simplicity of Removing Local Admin Rights

Understanding Endpoint Privilege Management: The Path to Effective Least Privilege The challenge of managing local...

CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild

Critical Command Injection Vulnerability in Progress LoadMaster Identified by CISA The U.S. Cybersecurity and Infrastructure...