V-Help
← All news
Security

StormEncryptor: New Ransomware from Former Medusa Affiliate

StormEncryptor: New Ransomware from Former Medusa Affiliate

Photo: BleepingComputer

Quick answer

StormEncryptor ransomware is now being used by Storm-1175, a group previously linked to Medusa. Attacks begin with exploitation of CVE-2026-18577 in N-central RMM, enabling rapid data encryption and network compromise.

Microsoft Threat Intelligence has identified a new wave of attacks using the StormEncryptor ransomware. The campaign is linked to Storm-1175, a group previously known as a Medusa affiliate. The attackers exploit CVE-2026-18577 in N-central remote monitoring and management (RMM) software, enabling rapid access to corporate networks.

Once inside, the threat actors deploy remote access tools like AnyDesk and SimpleHelp, along with Advanced IP Scanner for network reconnaissance. Credential theft is facilitated by Mimikatz, which extracts data from the LSASS process. Encrypted files receive the '.encrypted' extension, and each directory contains a ransom note titled '!!!README_FIRST!!!.txt'.

Microsoft notes that Storm-1175 operates with alarming speed: from initial breach to ransomware deployment takes just days. N-able has released a patch for the vulnerability, and administrators are urged to update systems urgently. Organizations should also scan for suspicious files, such as svchost.exe in the Documents folder, and block connections to known malicious IP addresses.

Common questions

Who is behind the StormEncryptor attacks?
The attacks are attributed to the cybercrime group Storm-1175, formerly associated with the Medusa ransomware. Microsoft Threat Intelligence tracks its activity and links it to the exploitation of enterprise system vulnerabilities.
Which vulnerability does Storm-1175 exploit?
The group exploits CVE-2026-18577 in N-central remote monitoring and management (RMM) software. This flaw allows authentication bypass and unauthorized system access.
How can organizations protect against StormEncryptor?
Apply the 2026.3 HF1 patch for N-central immediately. Monitor for suspicious activity, such as AnyDesk or Mimikatz execution, and scan systems for signs of compromise.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer