"Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use," Microsoft wrote.
Microsoft Threat Intelligence: a former Medusa affiliate returns with a new locker
Microsoft Threat Intelligence reports that a financially motivated actor previously linked to the Medusa ransomware operation is now operating under the tracked designation Storm-1175 and deploying a new ransomware family called StormEncryptor. The company says this marks the actor’s first observed activity since April 2026 and represents a shift away from Medusa ransomware toward the newly identified C++ ransomware strain.
Technical profile of StormEncryptor
Microsoft’s analysis describes StormEncryptor as a C++ program that appends encrypted files with the ".encrypted" extension and drops a ransom note named '!!!README_FIRST!!!.txt' into every scanned directory. The note gives victims three days to initiate contact and negotiate payment; if no contact is made, the attackers threaten to publish stolen data online. Microsoft emphasized that Storm-1175 “is known to rapidly move from initial access to data exfiltration and ransomware deployment, often within a few days.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleExploitation path: CVE-2026-18577 in N-central RMM and the vendor response
Microsoft says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability in N-able’s N-central remote monitoring and management (RMM) product, tracked as CVE-2026-18577. N-able issued a hotfix — 2026.3 HF1/build 2026.3.1.7 — on August 2 and urged customers to install the patch immediately. N-able has previously advised administrators to look for indicators of compromise such as an svchost.exe file placed in users' Documents folders, a registered service named Cloudflared, and inbound connections from IP addresses listed in the vendor advisory.
Post-compromise actions and tooling observed
After gaining access to target networks, Microsoft reports Storm-1175 operators used remote-access tools and reconnaissance utilities to extend control and harvest credentials. The observed toolset included AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and Mimikatz to dump credentials from the Local Security Authority Subsystem Service (LSASS) process. The combination of fast movement, credential harvesting, and outboard remote-management tools aligns with the actor’s pattern of swift data theft followed by locker deployment.
What this means for technologists, affected enterprises, and procurement leaders
- Technologists and security teams: Monitor for the specific artifacts Microsoft flagged — the ".encrypted" extension, the '!!!README_FIRST!!!.txt' note, and the presence of svchost.exe in users' Documents folders or a Cloudflared service registration — and prioritize patching N-central instances with the 2026.3 HF1/build 2026.3.1.7 hotfix. Microsoft explicitly urged administrators to apply security patches as soon as possible.
- Affected enterprises and incident response teams: Expect rapid progression from initial access to exfiltration and encryption; Microsoft warns the actor can often complete these stages within a few days. Prepare to investigate use of AnyDesk, SimpleHelp, Advanced IP Scanner, and credential dumps from LSASS as part of containment and forensic work.
- Procurement and operations leaders running self-hosted RMM: The advisory from N-able and Microsoft’s findings underline the operational risk of exposed management consoles. Install vendor hotfixes immediately and audit RMM deployments for unusual inbound connections and unknown services identified in vendor guidance.
Microsoft’s assessment also notes the actor is believed to be China-based and had previously exploited zero-day and n-day flaws in a range of products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Ivanti Connect Secure, and JetBrains TeamCity. The transition to a new ransomware family and the continued use of rapid exploitation followed by credential harvesting and remote administration tools indicate a durable operational playbook.
For defenders, the immediate steps are concrete: apply the N-able hotfix released August 2, scan for the indicated artifacts and behaviors, and treat any signs of compromise as time-sensitive given the actor’s rapid tempo. For organizations that rely on self-hosted RMM, the incident reinforces that an exposed management plane can be the pivot to full-network compromise — and when the pivot is swift, so too must be the response.
Original reporting: BleepingComputer: New StormEncryptor ransomware used by former Medusa affiliate




