GBHackers

Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw


Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain, StormEncryptor, on August 2, 2026.

The activity represents Storm-1175’s first observed operation since April 2026 and signals a notable shift in its ransomware tooling.

The group was previously associated with Medusa ransomware deployments but is now using a custom C++-based payload designed to encrypt victims’ files and disrupt business operations.

Storm-1175 Launches StormEncryptor Ransomware Attacks

StormEncryptor appends the .encrypted extension to affected files and creates a ransom note, !!!README_FIRST!!!.txt, in every directory it scans.

The note instructs victims to contact the attackers via anonymized communication services and warns that stolen data could be published if payment demands are not met.

Microsoft has not confirmed the precise initial-access vulnerability abused in the campaign. However, the available timing and threat activity strongly suggest that Storm-1175 may be exploiting CVE-2026-18577, an authentication-bypass vulnerability affecting N-able products.

The flaw was publicly disclosed on August 2, 2026, the same day Microsoft observed the StormEncryptor activity, and was added to CISA’s Known Exploited Vulnerabilities catalog on August 3.

The rapid emergence of an apparent exploitation campaign is consistent with Storm-1175’s established operational pattern: weaponizing newly disclosed vulnerabilities before organizations can apply patches or mitigations.

Storm-1175 began (Source: Microsoft Threat Intelligence)
Storm-1175 began (Source: Microsoft Threat Intelligence)

Storm-1175 is known for high-velocity ransomware operations that capitalize on the gap between public vulnerability disclosure and widespread remediation.

Such campaigns can provide attackers with initial access to exposed or insufficiently secured infrastructure, particularly where internet-facing remote management services are involved.

Following initial access, Storm-1175 has been observed using legitimate and dual-use tools to expand access, identify systems, and prepare ransomware deployment.

Microsoft reported the use of AnyDesk or SimpleHelp remote monitoring and management tools, likely to establish or maintain remote access across compromised environments. The actor also uses Advanced IP Scanner to enumerate hosts and discover systems within a target network.

For credential theft, Storm-1175 has been linked to dumping Local Security Authority Subsystem Service (LSASS) memory using Mimikatz, a widely abused post-exploitation utility capable of extracting credentials and authentication material from Windows systems.

This toolset reflects hands-on-keyboard ransomware tradecraft rather than a purely automated intrusion. By combining remote administration tools, network discovery, and credential theft, attackers can move laterally, access high-value systems, and deploy ransomware more broadly across an environment.

Mitigation

Microsoft Defender Antivirus detects the StormEncryptor sample with SHA-256 hash c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054 as Ransom:Win64/StormEncryptor.

Microsoft Defender for Endpoint can also generate alerts associated with the operation, including “Hands-on-keyboard attack involving multiple devices” and “Potential human-operated malicious activity.”

Organizations using potentially affected N-able products should prioritize applying vendor security updates and follow CISA guidance for CVE-2026-18577.

Security teams should also investigate unexpected use of AnyDesk, SimpleHelp, Advanced IP Scanner, Mimikatz, LSASS-access activity, and the creation of files named !!!README_FIRST!!!.txt.

Given Storm-1175’s rapid progression from initial access to data theft and encryption, prompt patching, endpoint monitoring, and the isolation of suspected compromised systems are critical to reducing the ransomware’s impact.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world



Source link