China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft Threat Intelligence disclosed that Storm-1175, a financially motivated China-linked threat actor, has deployed a previously undocumented ransomware strain called StormEncryptor โ a C++ locker that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ransom notes, marking a shift from the actor's prior use of Medusa.
Summary
| Field | Detail |
|---|---|
| Threat Actor | Storm-1175 (China-linked, financially motivated) |
| Attributed by | Microsoft Threat Intelligence |
| Malware | StormEncryptor โ previously undocumented C++ locker |
| File marking | Appends .encrypted; drops !!!README_FIRST!!!.txt ransom notes |
| Shift | From prior use of Medusa ransomware |
| Likely initial access | Exploitation of CVE-2026-18577 in N-able N-central |
| Confidence | Probable (vendor analysis; exploitation path assessed, not directly observed) |
| Date | 2026-08-10 |
Key Details
- StormEncryptor appends
.encryptedto encrypted files and drops!!!README_FIRST!!!.txtransom notes. - Marks a shift away from Medusa for this actor.
- Microsoft assesses the initial-access vector is likely exploitation of CVE-2026-18577 in N-able N-central, tying the new ransomware to the same RMM vulnerability that drove the week's hotfix cycle.
Significance
The N-able N-central exploitation chain is directly relevant to Australian managed service providers, who rely heavily on RMM platforms to manage client endpoints โ a compromised N-central instance grants attackers the same elevated access legitimate technicians use. The disclosure that China-linked Storm-1175 ransomware now leverages this flaw means Australian MSPs still running affected N-central versions should treat the vendor's Hotfix 2 as urgent and audit server access logs. This is the first documented end-to-end ransomware deployment on the RMM attack surface.
Related Pages
- Cve 2026 18577 Nable Ncentral Auth Bypass โ The N-able N-central vulnerability (CVE-2026-18577)
Source
- The Hacker News โ 2026-08-10
Sources: raw/digests/Cyber-Digest-2026-08-11