
StormEncryptor Campaign
Indicators of Compromise
No domains found for this campaign
APT Groups1
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
The following detection signals are derived directly from Storm-1175's observed tactics, techniques, and infrastructure.
Related Technique(s) | Detection Signal |
Monitor N-central authentication and Take Control session logs for exploitation of CVE-2026-18577, unexpected admin-level access, and anomalous console logins consistent with the disclosed patch bypass for CVE-2026-18556. | |
Alert on authentication bypass patterns against N-central accounts and unusual session establishment inconsistent with normal administrator behavior. | |
Detect abuse of the N-central Take Control feature to pivot into managed endpoints, and unexpected use of AnyDesk or SimpleHelp remote access sessions. | |
Flag execution of Advanced IP Scanner or similar network discovery tools shortly after initial access to an N-central managed endpoint. | |
Monitor for Mimikatz execution and LSASS memory access consistent with credential dumping on compromised endpoints. | |
Alert on data staging and exfiltration activity originating from N-central managed endpoints shortly before ransomware deployment. | |
Monitor for mass file renaming with the .encrypted extension, creation of the ransom note !!!README_FIRST!!!.txt in scanned directories, and registration of a service named Cloudflared used for tunnel-based persistence. |