Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-11 ยท updated: 2026-08-11 ยท tags: [incident, ransomware, china, nation-state, storm-1175, n-central, rmm, cve-2026-18577, sector-technology] ยท confidence: medium ยท affected_sectors: [technology, managed-service-providers, critical-infrastructure] ยท au_impact: true

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft Threat Intelligence disclosed that Storm-1175, a financially motivated China-linked threat actor, has deployed a previously undocumented ransomware strain called StormEncryptor โ€” a C++ locker that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ransom notes, marking a shift from the actor's prior use of Medusa.

Summary

Field Detail
Threat Actor Storm-1175 (China-linked, financially motivated)
Attributed by Microsoft Threat Intelligence
Malware StormEncryptor โ€” previously undocumented C++ locker
File marking Appends .encrypted; drops !!!README_FIRST!!!.txt ransom notes
Shift From prior use of Medusa ransomware
Likely initial access Exploitation of CVE-2026-18577 in N-able N-central
Confidence Probable (vendor analysis; exploitation path assessed, not directly observed)
Date 2026-08-10

Key Details

  • StormEncryptor appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ransom notes.
  • Marks a shift away from Medusa for this actor.
  • Microsoft assesses the initial-access vector is likely exploitation of CVE-2026-18577 in N-able N-central, tying the new ransomware to the same RMM vulnerability that drove the week's hotfix cycle.

Significance

The N-able N-central exploitation chain is directly relevant to Australian managed service providers, who rely heavily on RMM platforms to manage client endpoints โ€” a compromised N-central instance grants attackers the same elevated access legitimate technicians use. The disclosure that China-linked Storm-1175 ransomware now leverages this flaw means Australian MSPs still running affected N-central versions should treat the vendor's Hotfix 2 as urgent and audit server access logs. This is the first documented end-to-end ransomware deployment on the RMM attack surface.

Related Pages

Source

Sources: raw/digests/Cyber-Digest-2026-08-11