
Storm-1175 Deploys New 'StormEncryptor' Ransomware via Exploited N-able MSP Vulnerabilities
Microsoft Threat Intelligence has identified a high-velocity campaign by Storm-1175 leveraging a recently disclosed N-able vulnerability to deploy the novel StormEncryptor ransomware family against global MSPs.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Microsoft Threat Intelligence
- Read Time:
- 5 min
Executive Summary
On August 8, 2026, Microsoft Threat Intelligence reported the emergence of a new ransomware family dubbed "StormEncryptor," currently being deployed by the financially motivated threat actor Storm-1175. This campaign specifically targets Managed Service Providers (MSPs) by exploiting a critical vulnerability in N-able software that was recently added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The speed of these attacks suggests a highly automated exploitation chain designed to compromise downstream customers before patches can be widely implemented. This development represents a significant escalation in supply chain targeting, as reported in Storm-1175 Deploys New StormEncryptor Ransomware, Likely Exploiting N-able Flaw.
Threat Analysis
Storm-1175 has historically been known for high-velocity campaigns, often exploiting the "sweet spot" between vulnerability disclosure and patch saturation. The current operation marks a significant evolution, moving from known payloads like Medusa to the proprietary StormEncryptor. By targeting MSPs, the group achieves a "force multiplier" effect, gaining access to dozens or hundreds of client environments through a single point of entry. This supply chain approach is particularly devastating for small-to-medium businesses (SMBs) that rely on MSPs for their primary security posture. The group's ability to pivot from initial access to full-scale encryption within hours underscores the maturity of their operational playbook.
Technical Details
The campaign leverages a critical vulnerability in N-able's management suite, which was added to the CISA KEV catalog on August 4, 2026, as noted in News – August 2026 - Cyber Security Review. Once initial access is gained, Storm-1175 utilizes living-off-the-land (LotL) techniques to move laterally. StormEncryptor itself is a sophisticated C++ based ransomware that utilizes multi-threaded encryption to maximize speed. It targets specific file extensions associated with databases, backups, and virtual machine disks. Preliminary analysis indicates the use of a custom "Storm-Gate" loader to deliver the final payload, which attempts to disable local security agents and clear Windows Event Logs to hinder forensic investigation. The group also employs PowerShell scripts for credential harvesting and automated discovery of high-value targets within the victim's network.
Attribution Assessment
Microsoft attributes this activity to Storm-1175 with high confidence. While the group's tactics overlap with other ransomware-as-a-service (RaaS) affiliates, the unique deployment of StormEncryptor and the specific focus on N-able vulnerabilities distinguish this cluster. Storm-1175 is assessed to be a financially motivated cybercriminal entity, likely operating out of Eastern Europe, though they maintain a global targeting profile. Their recent activity mirrors the "high velocity" patterns previously observed in their Medusa deployments, where they exploited zero-day and N-day flaws with remarkable speed.
Implications
The exploitation of MSP tools represents a critical risk to the global supply chain. If successful, Storm-1175 can paralyze critical infrastructure and essential services across multiple sectors simultaneously. The inclusion of the N-able flaw in the CISA KEV catalog underscores the severity, as federal agencies and private sector partners are now under strict timelines to remediate the vulnerability. The potential for widespread disruption is high, given the reliance of modern businesses on managed services. This campaign follows a trend of targeting critical infrastructure, similar to the recent attacks on Minnesota water utilities reported in 3rd August – Threat Intelligence Report - Check Point Research.
Recommendations
Organizations using N-able products must prioritize the immediate application of security updates as directed by the vendor. MSPs should implement strict network segmentation between their management infrastructure and client environments. Furthermore, the enforcement of phishing-resistant Multi-Factor Authentication (MFA) and the deployment of advanced Endpoint Detection and Response (EDR) solutions are essential to detect the lateral movement and credential harvesting phases of the Storm-1175 kill chain. Regular offline backups and incident response drills are also recommended to mitigate the impact of a successful encryption event. Security teams should also monitor for unusual activity involving administrative tools and unauthorized PowerShell execution.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Professional and Healthcare Sectors

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

