< Back to all clusters
[TECHNOLOGY] · China · 4 sources

started · updated

Microsoft identifies StormEncryptor ransomware from Chinese hacking group

Microsoft Threat Intelligence has identified a new cyber threat involving a ransomware strain called StormEncryptor. The malware is being deployed by Storm-1175, a financially motivated hacking group originating from China.

Storm-1175, previously known as an affiliate of the Medusa ransomware, has shifted strategy by developing its own custom malware written in C++. The ransomware targets unpatched systems, specifically exploiting vulnerabilities such as CVE-2026-18577 in N-able N-central remote management software. This vulnerability allows attackers to bypass authentication mechanisms to gain system access.

Once a system is compromised, StormEncryptor encrypts files by adding a ". encrypted" extension and leaves a ransom note titled "!!!README_FIRST!!!.txt" in affected directories. The attackers provide victims with a three-day window to negotiate payment, threatening to publish stolen data if demands are not met. The group is noted for its rapid exploitation capabilities, sometimes launching attacks within 24 hours of a vulnerability being publicly disclosed.

Entities

Microsoft · N-able · Storm-1175 · StormEncryptor