New StormEncryptor ransomware used by former Medusa affiliate

New StormEncryptor ransomware used by former Medusa affiliate
Microsoft says the threat actor Storm-1175, previously linked to Medusa ransomware, is now deploying a new ransomware strain called StormEncryptor after likely exploiting CVE-2026-18577 in N-central. The malware appends the .encrypted extension, drops a ransom note named !!!README_FIRST!!!.txt, and threatens to leak stolen data if victims do not pay within three days. #Storm-1175 #StormEncryptor #CVE-2026-18577 #N-central #Medusa

Keypoints

  • Storm-1175 has shifted from Medusa ransomware to a new strain called StormEncryptor.
  • The attacks likely began with exploitation of CVE-2026-18577 in N-central.
  • StormEncryptor appends the .encrypted extension and drops !!!README_FIRST!!!.txt ransom notes.
  • The actor used AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz during the intrusion.
  • N-able released hotfix 2026.3 HF1/build 2026.3.1.7 and urged immediate patching.

Read More: https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/