Microsoft has linked a new ransomware strain, StormEncryptor, to a threat actor previously associated with the Medusa ransomware operation.

The group, tracked as Storm-1175, likely exploited a recently disclosed N-central vulnerability before deploying the malware. Organisations running self-hosted N-central servers should apply the available hotfix immediately.

Microsoft says the group can move quickly from initial access to data theft and ransomware deployment.

Storm-1175 shifts away from Medusa

Storm-1175 is a financially motivated threat actor believed to operate from China. Microsoft previously linked the group to Medusa ransomware attacks.

The group has targeted vulnerable systems through zero-day and known security flaws. Its past targets include GoAnywhere MFT, SmarterMail, Microsoft Exchange, Ivanti Connect Secure and JetBrains TeamCity.

Microsoft last observed Storm-1175 activity in April 2026. The new campaign marks a shift from Medusa to StormEncryptor ransomware.

N-central flaw likely used for access

Microsoft said the recent attacks were likely preceded by exploitation of CVE-2026-18577. The vulnerability affects N-central, a remote monitoring and management platform.

Attackers can use vulnerable RMM tools to gain a foothold in corporate networks. From there, they may steal credentials, move between systems and deploy ransomware.

N-able released a hotfix for CVE-2026-18577 on August 2. The fix is available in N-central 2026.3 HF1, build 2026.3.1.7.

Administrators should install the update as soon as possible. They should also check their environments for signs of unauthorised access.

How StormEncryptor operates

StormEncryptor is ransomware written in C++. It encrypts victims’ files and adds the .encrypted extension.

The malware also places ransom notes in directories it scans. These notes give victims three days to contact the attackers.

If victims do not respond, the group threatens to publish stolen data. This tactic combines file encryption with data extortion.

Microsoft said the attackers used legitimate remote access tools after entering target networks. They also used network scanning and credential theft tools to expand their access.

Defenders urged to act quickly

Microsoft warned that Storm-1175 can move from initial access to ransomware deployment within days.

N-able previously advised administrators to investigate possible signs of compromise. These include an unexpected svchost.exe file in a user’s Documents folder and a service named Cloudflared.

The company also provided a list of suspicious IP addresses in its advisory. Organisations should review that guidance and investigate any matching activity.

Fast patching remains the most important step. Security teams should also restrict remote access, monitor unusual administrator activity and review their N-central servers for compromise.


0 responses to “New StormEncryptor Ransomware Used by Former Medusa Affiliate”