Campaigns
StormEncryptor Campaign

StormEncryptor Campaign

RansomwareRMM ExploitationData ExfiltrationFinancial MotivationN-day Weaponization
Storm-1175, a China-based financially motivated threat actor, began deploying a previously undocumented ransomware strain called StormEncryptor on 02.08.2026. The activity likely stems from exploitation of CVE-2026-18577, an authentication bypass vulnerability in N-able N-central that represents a patch bypass for the earlier CVE-2026-18556. This marks Storm-1175's first observed activity since April 2026 and a shift away from the group's previous use of Medusa ransomware.

Indicators of Compromise

No domains found for this campaign

APT Groups1

Storm-1175CN

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION&DETECTION

The following detection signals are derived directly from Storm-1175's observed tactics, techniques, and infrastructure.

Related Technique(s)

Detection Signal

T1190

Monitor N-central authentication and Take Control session logs for exploitation of CVE-2026-18577, unexpected admin-level access, and anomalous console logins consistent with the disclosed patch bypass for CVE-2026-18556.

T1078

Alert on authentication bypass patterns against N-central accounts and unusual session establishment inconsistent with normal administrator behavior.

T1021

Detect abuse of the N-central Take Control feature to pivot into managed endpoints, and unexpected use of AnyDesk or SimpleHelp remote access sessions.

T1087 / T1018

Flag execution of Advanced IP Scanner or similar network discovery tools shortly after initial access to an N-central managed endpoint.

T1003.001

Monitor for Mimikatz execution and LSASS memory access consistent with credential dumping on compromised endpoints.

T1560 / T1041

Alert on data staging and exfiltration activity originating from N-central managed endpoints shortly before ransomware deployment.

T1486

Monitor for mass file renaming with the .encrypted extension, creation of the ransom note !!!README_FIRST!!!.txt in scanned directories, and registration of a service named Cloudflared used for tunnel-based persistence.

Observed Countries3

AU (813)
GB (67)
US (787)