Microsoft says the threat actor Storm-1175, previously linked to Medusa ransomware, is now deploying a new ransomware strain called StormEncryptor after likely exploiting CVE-2026-18577 in N-central. The malware appends the .encrypted extension, drops a ransom note named !!!README_FIRST!!!.txt, and threatens to leak stolen data if victims do not pay within three days. #Storm-1175 #StormEncryptor #CVE-2026-18577 #N-central #Medusa
Keypoints
- Storm-1175 has shifted from Medusa ransomware to a new strain called StormEncryptor.
- The attacks likely began with exploitation of CVE-2026-18577 in N-central.
- StormEncryptor appends the .encrypted extension and drops !!!README_FIRST!!!.txt ransom notes.
- The actor used AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz during the intrusion.
- N-able released hotfix 2026.3 HF1/build 2026.3.1.7 and urged immediate patching.