Friday, September 11, 2026

Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw

Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain, StormEncryptor, on August 2, 2026.

The activity represents Storm-1175’s first observed operation since April 2026 and signals a notable shift in its ransomware tooling.

The group was previously associated with Medusa ransomware deployments but is now using a custom C++-based payload designed to encrypt victims’ files and disrupt business operations.

Storm-1175 Launches StormEncryptor Ransomware Attacks

StormEncryptor appends the .encrypted extension to affected files and creates a ransom note, !!!README_FIRST!!!.txt, in every directory it scans.

The note instructs victims to contact the attackers via anonymized communication services and warns that stolen data could be published if payment demands are not met.

Microsoft has not confirmed the precise initial-access vulnerability abused in the campaign. However, the available timing and threat activity strongly suggest that Storm-1175 may be exploiting CVE-2026-18577, an authentication-bypass vulnerability affecting N-able products.

The flaw was publicly disclosed on August 2, 2026, the same day Microsoft observed the StormEncryptor activity, and was added to CISA’s Known Exploited Vulnerabilities catalog on August 3.

The rapid emergence of an apparent exploitation campaign is consistent with Storm-1175’s established operational pattern: weaponizing newly disclosed vulnerabilities before organizations can apply patches or mitigations.

Storm-1175 began (Source: Microsoft Threat Intelligence)
Storm-1175 began (Source: Microsoft Threat Intelligence)

Storm-1175 is known for high-velocity ransomware operations that capitalize on the gap between public vulnerability disclosure and widespread remediation.

Such campaigns can provide attackers with initial access to exposed or insufficiently secured infrastructure, particularly where internet-facing remote management services are involved.

Following initial access, Storm-1175 has been observed using legitimate and dual-use tools to expand access, identify systems, and prepare ransomware deployment.

Microsoft reported the use of AnyDesk or SimpleHelp remote monitoring and management tools, likely to establish or maintain remote access across compromised environments. The actor also uses Advanced IP Scanner to enumerate hosts and discover systems within a target network.

For credential theft, Storm-1175 has been linked to dumping Local Security Authority Subsystem Service (LSASS) memory using Mimikatz, a widely abused post-exploitation utility capable of extracting credentials and authentication material from Windows systems.

This toolset reflects hands-on-keyboard ransomware tradecraft rather than a purely automated intrusion. By combining remote administration tools, network discovery, and credential theft, attackers can move laterally, access high-value systems, and deploy ransomware more broadly across an environment.

Mitigation

Microsoft Defender Antivirus detects the StormEncryptor sample with SHA-256 hash c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054 as Ransom:Win64/StormEncryptor.

Microsoft Defender for Endpoint can also generate alerts associated with the operation, including “Hands-on-keyboard attack involving multiple devices” and “Potential human-operated malicious activity.”

Organizations using potentially affected N-able products should prioritize applying vendor security updates and follow CISA guidance for CVE-2026-18577.

Security teams should also investigate unexpected use of AnyDesk, SimpleHelp, Advanced IP Scanner, Mimikatz, LSASS-access activity, and the creation of files named !!!README_FIRST!!!.txt.

Given Storm-1175’s rapid progression from initial access to data theft and encryption, prompt patching, endpoint monitoring, and the isolation of suspected compromised systems are critical to reducing the ransomware’s impact.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News