Financially motivated hackers linked to China began deploying a new ransomware strain on August 2, possibly hours after exploiting a critical authentication bypass in N-able's remote monitoring and management software, Microsoft Threat Intelligence said Friday. The group, tracked as Storm-1175, returned with C++-based ransomware called StormEncryptor after several dormant months since April, marking a shift away from the Medusa ransomware that had thrust the group into the public eye.
Exploitation Outpaced the Patch
Microsoft said Storm-1175 likely exploited CVE-2026-18577, an authentication bypass in N-able's N-central product, on the same day the vulnerability was disclosed. N-able had first detected the actively exploited zero-day on July 31, and its initial patch proved incomplete — the later flaw, which allows a remote, unauthenticated attacker to gain administrative control of vulnerable RMM servers on-premises or in the cloud, was assigned a CVSS score of 8.2 and added to CISA's Known Exploited Vulnerabilities catalog a day after disclosure, according to Rapid7 and BankInfoSecurity.
"Storm-1175 is known to operate high-velocity ransomware campaigns that weaponize N-days, taking advantage of the window between vulnerability disclosure and patch adoption," Microsoft said. "Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible." The group moves from initial access to data exfiltration and encryption within days — sometimes under 24 hours — abusing AnyDesk or SimpleHelp remote access tools, Advanced IP Scanner for discovery, and Mimikatz to dump credentials from LSASS process memory, which can grant domain-wide compromise.
Victims Listed, Data Posted in Three Days
A flurry of victim companies has appeared on Storm-1175's ransom site over the past week, spanning e-commerce, fintech, healthcare and home security. The ransomware encrypts files and drops a ransom note threatening to publish stolen data within three days. Microsoft says the group's post-compromise playbook also includes PsExec to reach domain controllers and exfiltrate Active Directory data — a reminder that the RMM tooling trusted for remote administration has become the top initial-access vector for fast-moving ransomware crews this quarter.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.