Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Novo Nordisk and AWS bring agentic AI into drug discovery

    August 11, 2026

    New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

    August 11, 2026

    Nvidia’s $500 billion AI infrastructure push leaves crypto compute further behind

    August 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Novo Nordisk and AWS bring agentic AI into drug discovery
    • New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
    • Nvidia’s $500 billion AI infrastructure push leaves crypto compute further behind
    • Voyager 2 was running out of power. NASA just bought it more time
    • Permian Basin Community Seeks Fix for Radium in Its Drinking Water
    • Expro scores ‘major’ North Sea plug and abandonment win in UK waters
    • Is There Anyone Who Can Respond to My FOIA Requests? — ProPublica
    • MPs shouldn’t face abuse. Neither should their staff – but here’s what we deal with every day | Estelle Warhurst
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New StormEncryptor ransomware used by former Medusa affiliate

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.

    Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool.

    Storm-1175 is believed to be a China-based threat actor. It was previously linked to Medusa ransomware, targeting systems via zero-day and n-day flaws in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.

    image

    “Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use,” Microsoft states.

    The researchers found that StormEncryptor is a C++ malware that appends encrypted files with the “.encrypted” filename extension and drops a ransom note named ‘!!!README_FIRST!!!.txt’ into every scanned directory.

    The ransom note gives victims three days to reach out to the attacker and negotiate a ransom payment. Alternatively, the stolen data would be leaked online.

    StormEncryptor ransom note
    StormEncryptor ransom note
    Source: Microsoft

    After gaining access to the target network, the attacker used AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and the Mimikatz tool to dump credentials from the Local Security Authority Subsystem Service (LSASS) process.

    Microsoft says that Storm-1175 moves quickly from initial compromise to stealing data and deploying the locker, urging system administrators managing self-hosted N-central servers to take immediate action to secure the systems.

    “This threat actor is known to rapidly move from initial access to data exfiltration and ransomware deployment, often within a few days,” warned Microsoft.

    “Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”

    N-able addressed the CVE-2026-18577 vulnerability via a hotfix (2026.3 HF1/build 2026.3.1.7) released on August 2, urging customers to install the patch immediately.

    N-able previously recommended admins to check for signs of compromise such as an svchost.exe file in the Documents folders of users’ device, a registered service named Cloudflared, and inbound connections from the IP addresses listed in the advisory.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Affiliate Medusa ransomware StormEncryptor
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

    BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

    Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

    Mozilla Issues New Firefox GPG Key Following Exposure

    New Jersey, Alabama Join States Targeted in Water Cyberattacks

    OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Novo Nordisk and AWS bring agentic AI into drug discovery

    August 11, 2026

    New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

    August 11, 2026

    Nvidia’s $500 billion AI infrastructure push leaves crypto compute further behind

    August 11, 2026

    Voyager 2 was running out of power. NASA just bought it more time

    August 11, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Novo Nordisk and AWS bring agentic AI into drug discovery

    August 11, 2026

    New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

    August 11, 2026

    Nvidia’s $500 billion AI infrastructure push leaves crypto compute further behind

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.