Microsoft says Storm-1175, a China-linked financially motivated threat actor, has switched from Medusa to a new ransomware strain called StormEncryptor. The campaign likely abuses a newly disclosed N-able N-central flaw for access, then uses tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz before quickly exfiltrating data and encrypting systems. #Storm-1175 #StormEncryptor #Medusa #N-able #N-central #CVE-2026-18577 #CVE-2026-18556 #AnyDesk #SimpleHelp #Mimikatz
Keypoints
- Storm-1175 has deployed a new ransomware strain named StormEncryptor.
- The group previously relied on Medusa ransomware in its attacks.
- Microsoft suspects exploitation of CVE-2026-18577 in N-able N-central for initial access.
- Post-compromise activity includes AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz.
- Storm-1175 moves quickly from intrusion to data theft and ransomware deployment.
Read More: https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html