Microsoft Threat Intelligence has identified a significant shift in tactics by Storm-1175, a China-based financially motivated threat actor, which has begun deploying a new ransomware strain called StormEncryptor. The group, previously known for using Medusa ransomware, started using StormEncryptor on August 2, 2026. The new malware is written in C++ and encrypts files with an .encrypted extension, leaving a ransom note titled !!!README_FIRST!!!.txt in each affected directory. Microsoft believes the current campaign likely exploits CVE-2026-18577, an authentication bypass vulnerability in N-able that was disclosed on August 2, 2026, and added to CISA's Known Exploited Vulnerabilities catalog the following day.
Storm-1175 has established a pattern of rapidly weaponizing newly disclosed vulnerabilities before organizations can apply patches. Since 2023, Microsoft has observed the group exploiting over 16 different vulnerabilities across multiple platforms, including Microsoft Exchange, Ivanti Connect Secure, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, GoAnywhere MFT, and SmarterMail. In some cases, the threat actor has weaponized vulnerabilities within a single day of public disclosure, and has even used zero-day flaws before they became publicly known, demonstrating advanced capabilities and access to vulnerability intelligence.
The group's technical approach involves chaining multiple exploits to achieve deeper system access and targeting both Windows and Linux environments. After gaining initial access, Storm-1175 installs web shells or remote access tools such as AnyDesk and SimpleHelp, creates administrative accounts for persistence, and uses Advanced IP Scanner to map network infrastructure. The attackers employ credential theft tools like Mimikatz to dump LSASS credentials and move laterally through networks using PowerShell, PsExec, RDP, and Cloudflare tunnels. They also abuse legitimate remote monitoring and management tools and software like PDQ Deployer and Impacket to spread across compromised networks while weakening security defenses.
Storm-1175 primarily targets organizations in healthcare, education, finance, and services sectors across the United States, United Kingdom, and Australia. The group's speed is particularly concerning, with Microsoft reporting that attackers can progress from initial access to data theft and ransomware deployment within 24 hours in some cases. This compressed attack timeline leaves defenders with minimal time to detect and respond to intrusions before significant damage occurs. The focus on web-facing systems and newly disclosed vulnerabilities allows the group to maintain a persistent advantage over organizations that cannot patch quickly enough.
Organizations should prioritize immediate patching of all known vulnerabilities, particularly CVE-2026-18577 and other flaws listed in CISA's KEV catalog. Security teams should monitor for suspicious remote access tool installations, unauthorized administrative account creation, and unusual lateral movement activity. Implementing network segmentation, maintaining offline backups, and establishing rapid incident response procedures are critical defenses against Storm-1175's fast-moving attacks. Given the group's ability to exploit vulnerabilities within hours of disclosure, organizations must maintain aggressive patch management schedules and consider temporarily disabling or restricting access to vulnerable systems until patches can be applied.
Source: https://securityaffairs.com/197119/malware/storm-1175-replaces-medusa-with-new-stormencryptor-ransomware.html


