{"id":2310,"date":"2026-08-10T18:42:53","date_gmt":"2026-08-10T18:42:53","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2310"},"modified":"2026-08-10T18:42:53","modified_gmt":"2026-08-10T18:42:53","slug":"china-linked-hackers-deploy-new-stormencryptor-ransomware-likely-via-n-central-flaw","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2310","title":{"rendered":"China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 10, 2026<\/span><\/span><span class=\"p-tags\">Ransomware \/ Cybercrime<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjNv5C82jT_6YlarerdXnoAR_tT3E8xP65ZWuJfpvOKU9baBT5UACUTb88XvDQgQA6RrYuqPK3FstaqwacR9gDjD0qwk3HUYl0wK848phyphenhyphenFuqRrOA1AqdISQaA6tpEqg0n2XJIA22NeNNbhei1bAgcyghnc2qaVfSvh4fd9J1oD4xVi-DQcNSOYWQovyUst\/s1700-e365\/strom-ransomware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Microsoft has disclosed that <strong>Storm-1175<\/strong>, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called <strong>StormEncryptor<\/strong>.<\/p>\n<p>The use of StormEncryptor marks a shift from the adversary&#8217;s previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.<\/p>\n<p>\u00abStormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts,\u00bb Microsoft <a href=\"https:\/\/bsky.app\/profile\/threatintel.microsoft.com\/post\/3msjiybnb252n\" target=\"_blank\">noted<\/a> in a series of posts on Bluesky. \u00abIt then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory.\u00bb<\/p>\n<p>Although the exact vulnerability exploited by the threat actor as part of this campaign is unclear, the tech giant said it likely involves the exploitation of CVE-2026-18577, a newly disclosed security flaw in N-able N\u2011central, to obtain initial access.<\/p>\n<p>The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions. The vulnerabilities have since been flagged by the  U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited in the wild.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Storm-1175 is the name assigned to a <a href=\"https:\/\/x.com\/MsftSecIntel\/status\/1781353321267069292\" target=\"_blank\">China-based threat actor<\/a> with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2023-37679\" target=\"_blank\">CVE-2023-37679<\/a>, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2023-43208\" target=\"_blank\">CVE-2023-43208<\/a>), ConnectWise ScreenConnect (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2024-1709\" target=\"_blank\">CVE-2024-1709<\/a>, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2024-1708\" target=\"_blank\">CVE-2024-1708<\/a>), JetBrains TeamCity (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2024-27198\" target=\"_blank\">CVE-2024-27198<\/a>, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2024-27199\" target=\"_blank\">CVE-2024-27199<\/a>), and Fortinet FortiClient EMS (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2023-48788\" target=\"_blank\">CVE-2023-48788<\/a>).<\/p>\n<p>In an analysis published in October 2025, Microsoft also attributed the threat actor to the exploitation of a critical security vulnerability impacting Fortra GoAnywhere (CVE-2025-10035) to facilitate the deployment of Medusa ransomware.<\/p>\n<p>The group, per the Windows maker, weaponizes a combination of zero-days and N-day vulnerabilities to carry out high-velocity attacks and break into susceptible internet-facing systems by taking advantage of the window between vulnerability disclosure and patch adoption.<\/p>\n<p>\u00abIn this new activity, Storm-1175&#8217;s post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz,\u00bb it added.<\/p>\n<p>Storm-1175 has also been observed rapidly moving from initial access to data exfiltration and ransomware deployment, mostly within a few days, making it essential that customers apply the patches as soon as possible.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 10, 2026Ransomware \/ Cybercrime Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2311,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[479,229,70,338,2848,93,2978],"class_list":["post-2310","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-chinalinked","tag-deploy","tag-flaw","tag-hackers","tag-ncentral","tag-ransomware","tag-stormencryptor"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2310"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2310\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2311"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}