#StormEncryptor
On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
August 7, 2026 at 9:32 PM
Microsoft Defender Antivirus detects StormEncryptor (SHA-256: c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054) as Ransom:Win64/StormEncryptor.
August 7, 2026 at 9:40 PM
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
www.bleepingcomputer.com
August 10, 2026 at 5:42 PM
StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory.
August 7, 2026 at 9:34 PM
China-Linked Storm-1175 Deploys StormEncryptor as OpenAI Ships a Dedicated Cyber Model

https://blindthoughts.com/storm-1175-stormencryptor-openai-cyber-model

#ransomware #aisecurity #otsecurity #agenticai #openai
August 11, 2026 at 11:18 AM
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has …
#hackernews #microsoft #news
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then […]
securityaffairs.com
August 14, 2026 at 8:27 AM
Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use.
August 7, 2026 at 9:33 PM
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw gbhackers.com/storm-1175-l...
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain,...
gbhackers.com
August 9, 2026 at 10:42 AM
Great reminder! Cyber threats like #StormEncryptor evolve fast. Always keep your software updated and back up your data regularly to stay protected. Stay safe out there! 🛡️ #CyberSecurity
August 10, 2026 at 7:14 PM
StormEncryptor: come l’ex affiliato Medusa Storm-1175 ha trasformato N-central in un launchpad ransomware
il blog: insicurezzadigitale.com/stormencrypt...

#cybersecurity #china #cybercrime #infosec #medusa #ncentral #ransomware #rmm #storm1175 #supplychain
August 12, 2026 at 10:34 AM
Cloud roundup: New ransomware exploits N-central bug

Microsoft ties new StormEncryptor ransomware to an N-able N-central auth bypass, plus new AWS EC2 health checks and DRS UEFI support for Linux failovers.
Cloud roundup: New ransomware exploits N-central bug
Microsoft ties new StormEncryptor ransomware to an N-able N-central auth bypass, plus new AWS EC2 health checks and DRS UEFI support for Linux failovers.
jstgtech.com
August 11, 2026 at 2:00 AM
中国関連のハッカー集団が、N-centralの脆弱性を悪用したとみられる新たなランサムウェア「StormEncryptor」を展開

マイクロソフトは、中国と関連のある金銭目的の脅威アクターであるStorm-1175が、これまで報告されていなかったStormEncryptorと呼ばれるランサムウェアを展開したことを明らかにした。

マイクロソフトの脅威インテリジェンスチームによると、StormEncryptorの使用は、攻撃者が以前使用していたMedusaランサムウェアからの転換点となる。

「StormEncryptorはC++で記述されており、暗号化するファイルにファイル名拡張子.e...
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft says Storm-1175 is deploying new StormEncryptor ransomware, likely after exploiting N-able N-central CVE-2026-18577 for access.
thehackernews.com
September 12, 2026 at 6:27 AM
元メデューサ関連企業が使用する新たなランサムウェア「StormEncryptor」

以前はメデューサ・ランサムウェア攻撃に関与していた、金銭目的の脅威アクターが、ストームエンクリプターと呼ばれる新たなランサムウェアを展開している。

Microsoft Threat Intelligenceは、攻撃者をStorm-1175として追跡しており、最近の攻撃は、N-centralリモート監視および管理(RMM)ツールにおける認証バイパスの脆弱性(CVE-2026-18577)の悪用が先行した可能性が高いと述べています。

Storm-1175は中国を拠点とする脅威アクターによるものと考えられ...
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
www.bleepingcomputer.com
September 12, 2026 at 6:24 AM
Storm-1175がN-ableのセキュリティ脆弱性を利用してStormEncryptorランサムウェア攻撃を開始

Microsoft Threat Intelligenceは、金銭目的の脅威アクターであるStorm-1175による新たなランサムウェア攻撃キャンペーンを特定しました。このキャンペーンは、これまで記録されていなかったランサムウェアの一種であるStormEncryptorを2026年8月2日から展開し始めました。

今回の活動は、Storm-1175が2026年4月以来初めて観測された作戦であり、ランサムウェアのツールに顕著な変化が見られることを示している。

このグルー...
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain,...
gbhackers.com
September 7, 2026 at 1:08 PM
中国関連のハッカー集団が、人気のサイバーセキュリティツールをランサムウェアの発射台として利用していると、マイクロソフトが警告。

中国と関連のある、金銭目的の攻撃者が、広く使われているサイバーセキュリティソフトウェアに影響を与える重大な脆弱性を悪用し、サプライチェーン攻撃を仕掛けていると考えられている。この攻撃では、ハッカーがカスタマイズされたランサムウェアを、連鎖的に被害を受けた多数のネットワークに展開する可能性がある。

マイクロソフトの脅威インテリジェンスは今週末、Storm-1175グループが8月2日からStormEncryptorと呼ばれる新たなランサムウェアを展開し始めたと警...
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.
therecord.media
September 8, 2026 at 7:58 PM
Storm-1175 Deploys StormEncryptor Ransomware After N-able N-central Vulnerability Exploitation #CyberAttacks #CyberSecurityRansomwareAttacks
Storm-1175 Deploys StormEncryptor Ransomware After N-able N-central Vulnerability Exploitation
 Financially motivated hackers believed to be based in China are using a new ransomware for the first time after targeting a vulnerability in the N-central remote monitoring and management software. The threat group, which goes by the name Storm-1175, started deploying C++ StormEncryptor ransomware on August 2, following several months of inactivity since April, Microsoft Threat Intelligence said today.  It marks a departure from the Medusa ransomware previously used by the group. Microsoft says that Storm-1175 most likely used a publicly known zero-day vulnerability, CVE-2026-18577, which was identified as the weakness Storm-1175 attackers used to gain unauthorized access to N-central. N-central is a remote monitoring and management solution used to track and patch servers and endpoints, Microsoft says.  It means that successful exploitation of the vulnerability allows the attackers to target downstream organizations managed by the N-central server. N-able released a statement saying that it identified active exploitation of the zero-day vulnerability for the first time on July 31. Its initial advisory underestimated the scope of the problem, while the first patch was ineffective against active attacks. The company later released two additional emergency patches.  Rapid7 reports that CVE-2026-18577 was published on August 2, following an ineffective attempt to address another authentication bypass vulnerability, CVE-2026-18556. The newly discovered weakness has a CVSS score of 8.2 and was added to the CISA Known Exploited Vulnerabilities catalog on August 3. Huntress says that attackers could abuse Take Control Manager to deploy Cloudflare-based tunnels on the N-central servers and gain access to downstream managed endpoints as well as the initial compromise via Take Control Manager.   Microsoft notes that Storm-1175 actors are accelerating the ransomware lifecycle and are already targeting downstream victims for ransom within 24 hours of initial access. The group is using AnyDesk or SimpleHelp, Advanced IP Scanner for reconnaissance, and Mimikatz to dump credentials from the LSASS process. Storm-1175 ransomware encrypts files and demands payment, threatening to release the data within three days. Several organizations, including companies involved in e-commerce, fintech, healthcare, and home security, have been reported on the group’s ransomware site. Storm-1175’s ransomware activity is similar to the Medusa ransomware campaigns previously attributed to the same hacking group.  Microsoft says in its report that Storm-1175 actors are also abusing legitimate remote monitoring and management software in order to maintain persistent access to the corporate network and downstream organizations. The company says that attackers can use Take Control Manager to deploy additional implants, establish alternate C2 channels, and interact with the compromised servers or endpoints.  Attackers could use Remote Desktop Protocol (RDP) to connect to the domain controllers and install software such as PSExec or Windows Management Instrumentation to access other computers. With the domain controllers compromised, the attackers would be able to steal Active Directory data, including user credentials and the hashes of passwords, to gain more visibility and control over the corporate network.
dlvr.it
August 30, 2026 at 1:57 PM
警告:極めて危険なマルウェアです。 - Vietnam. vn

ハノイは、RedHookとStormEncryptorという2種類のマルウェアが、Androidスマートフォンを乗っ取り、ワンタイムパスワード(OTP)を盗み、不正な取引を行い、 ...
www.vietnam.vn/ja/canh-bao-...
警告:極めて危険なマルウェアです。
ハノイは、RedHookとStormEncryptorという2種類のマルウェアが、Androidスマートフォンを乗っ取り、ワンタイムパスワード(OTP)を盗み、不正な取引を行い、ランサムウェアを大規模に拡散する能力を持っていると警告している。ドンナイ省では、2026年の最初の8か月間で42,676件のマルウェアサンプルが分離・処理された。
www.vietnam.vn
August 28, 2026 at 11:42 PM
What is in a new ransomware name? A new strain of ransomware...

Learn how Storm-1175, a ransomware-focused hacking group that researchers have linked to China based on the group’s tactics, targets, and operational infrastructure is now deploying StormEncryptor: cybelangel.com/blog/china-l...
August 25, 2026 at 7:37 AM
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw thehackernews.com/2026/08/chin...
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft says Storm-1175 is deploying new StormEncryptor ransomware, likely after exploiting N-able N-central CVE-2026-18577 for access.
thehackernews.com
August 16, 2026 at 9:12 PM
August 14, 2026 at 1:05 AM
August 14, 2026 at 12:05 AM