China-linked crew drops StormEncryptor after N-central raids

China-linked crew drops StormEncryptor after N-central raids.

CSBadmin
2 Min Read

Organizations running N-able N-central should confirm they are on the patched release: Microsoft says a China-linked actor it tracks as Storm-1175 has deployed a previously undocumented ransomware strain called StormEncryptor, likely after exploiting a recently patched N-central flaw.

Built in C++, StormEncryptor renames encrypted files with a .encrypted suffix and leaves a note called !!!README_FIRST!!!.txt in each scanned folder. Microsoft Threat Intelligence says its use marks a shift from the adversary’s previous reliance on Medusa ransomware.

Defenders should look for .encrypted file extensions and the README FIRST ransom note, and review environments for signs of the strain. Microsoft has published indicators of compromise and detection guidance.

Although the exact vulnerability exploited in this campaign is unclear, Microsoft says it likely involves CVE-2026-18577, a newly disclosed flaw in N-able N-central assessed as a patch bypass for CVE-2026-18556. Both allow authentication bypass and account takeover in susceptible versions, and CISA has flagged both as actively exploited in the wild.

Microsoft tracks Storm-1175 as a China-based, money-driven group that has dropped Medusa ransomware after abusing flaws in Mirth Connect, ConnectWise ScreenConnect, and JetBrains TeamCity. N-able previously shipped hotfixes for the N-central flaws after attackers were observed moving from hijacked servers to managed customer environments.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.