Microsoft Threat Intelligence has identified a new ransomware campaign by Storm-1175 deploying the previously undocumented StormEncryptor strain, which appends the .encrypted extension and drops !!!README_FIRST!!!.txt ransom notes. The activity may be linked to exploitation of CVE-2026-18577 in N-able products, with the attackers using tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz to expand access and prepare for encryption. #Storm1175 #StormEncryptor #CVE202618577 #Nable #AnyDesk #SimpleHelp #AdvancedIPScanner #Mimikatz
Keypoints
- Storm-1175 launched a new campaign using the StormEncryptor ransomware strain.
- StormEncryptor encrypts files with the .encrypted extension and creates !!!README_FIRST!!!.txt notes.
- The campaign may be exploiting CVE-2026-18577 in N-able products.
- Storm-1175 uses AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz after initial access.
- Microsoft recommends patching, monitoring for suspicious tools, and isolating compromised systems quickly.
Read More: https://gbhackers.com/storm-1175-launches-stormencryptor-ransomware-attacks/