Skip to main content
Emerging ThreatsMalware & Ransomware

China-Linked Hackers Deploy StormEncryptor Ransomware via N-central Flaw

A typical office setting with computers and a blurred server room door in the foreground.

"StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts," Microsoft noted in a series of posts on Bluesky. "It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory."

Microsoft on StormEncryptor

Microsoft's Threat Intelligence Team disclosed a previously undocumented ransomware strain it names StormEncryptor, deployed by a financially motivated actor tracked as Storm-1175 and linked to China. The company described the malware's basic footprint: a C++ program that appends the extension .encrypted to encrypted files and places a ransom note titled !!!README_FIRST!!!.txt in every directory it scans.

Initial access: likely N‑able N‑central CVE‑2026‑18577

Microsoft said the precise vulnerability exploited in this campaign remains unclear but assessed it likely involves the exploitation of CVE-2026-18577, a newly disclosed flaw in N‑able N‑central. The vendor vulnerability is described as a patch bypass for CVE-2026-18556; both flaws allow authentication bypass and account takeover in susceptible versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged these vulnerabilities as actively exploited in the wild.

Storm-1175's exploitation history and pattern

The group tracked as Storm-1175 has an established pattern of weaponizing both zero-days and N-day vulnerabilities to move quickly against internet-facing systems, Microsoft said. The threat actor previously deployed Medusa ransomware after exploiting vulnerabilities in multiple products: Mirth Connect (CVE-2023-37679, CVE-2023-43208), ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708), JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199), and Fortinet FortiClient EMS (CVE-2023-48788).

In an October 2025 analysis, Microsoft attributed exploitation of a critical Fortra GoAnywhere vulnerability (CVE-2025-10035) to the same actor, noting the group’s habit of exploiting the window between vulnerability disclosure and patch adoption to conduct "high-velocity attacks."

Post‑compromise behavior and operational tempo

Microsoft detailed the actor's post-compromise toolkit and behavior. "In this new activity, Storm-1175's post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz," the Windows maker said. The group has been observed moving rapidly from initial access to data exfiltration and ransomware deployment — mostly within a few days — underscoring the operational tempo that defenders face.

What this means for security teams, procurement leaders, and CISA

  • Security teams: Microsoft emphasized speed. Because Storm-1175 moves from access to exfiltration and encryption in "mostly within a few days," affected customers are urged to apply available patches immediately and monitor for indicators consistent with AnyDesk, SimpleHelp, Advanced IP Scanner, and LSASS dumps via Mimikatz.
  • Procurement leaders and product owners: The likely involvement of CVE-2026-18577 in N‑able N‑central highlights the exposure that can follow vulnerable internet-facing management platforms; organizations running such products should inventory instances and prioritize patching.
  • CISA and federal responders: CISA has flagged CVE-2026-18577 and CVE-2026-18556 as actively exploited. That designation places these flaws on the active-threat radar and signals continued monitoring and advisory activity by U.S. federal cybersecurity authorities.

The practical takeaway is simple and stark: Microsoft says customers must apply the patches as soon as possible. Storm-1175's shift from Medusa to a new, undocumented strain called StormEncryptor — combined with a history of exploiting newly disclosed and known flaws for fast, automated intrusions — leaves a narrow window for defenders. Organizations running N‑able N‑central or other internet-facing management tools should assume urgency and act accordingly.

Original reporting: https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html