
Storm-1175 Deploys New StormEncryptor Ransomware via N-able Vulnerability Exploitation
Microsoft Threat Intelligence has identified a new campaign by Storm-1175 utilizing the previously unseen StormEncryptor ransomware. The group is actively exploiting N-able security flaws to gain initial access.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-33012
- Source:
- Microsoft Threat Intelligence
- Read Time:
- 4 min
Executive Summary
Microsoft Threat Intelligence (MSTIC) has uncovered a sophisticated campaign by the threat actor tracked as Storm-1175. This group is deploying a brand-new ransomware strain dubbed "StormEncryptor." The campaign, which intensified in early August 2026, specifically targets Managed Service Providers (MSPs) by exploiting a critical vulnerability in N-able remote monitoring and management software. This development represents a significant escalation in the threat landscape, as the group leverages supply-chain access to maximize the impact of their encryption routines across multiple downstream client environments simultaneously.
Threat Analysis
Storm-1175 is a financially motivated actor that has recently pivoted from data exfiltration-only attacks to full-scale ransomware deployment. By targeting MSPs, the group achieves a "one-to-many" impact, potentially compromising hundreds of downstream client networks through a single point of entry. This supply-chain approach marks a significant escalation in their operational tempo. The group appears to be moving away from the traditional "double extortion" model toward a more aggressive "triple extortion" strategy, which includes DDoS threats and direct harassment of the victim's clients to force payment. This shift suggests a high level of confidence in their ability to maintain persistence within compromised environments.
Technical Details
The primary vector involves the exploitation of a recently disclosed N-able vulnerability (CVE-2026-33012), which allows for remote code execution. Once access is gained, Storm-1175 deploys a PowerShell-based loader that fetches the StormEncryptor binary. StormEncryptor is written in Rust, making it highly efficient and difficult to reverse-engineer. It utilizes a hybrid encryption scheme (AES-256-GCM and RSA-4096) and specifically targets backup directories and shadow copies to prevent recovery. The malware also includes a modular component designed to scan for and disable common Endpoint Detection and Response (EDR) solutions before initiating the encryption process. This anti-analysis capability has allowed the group to evade detection in several high-profile incidents reported over the last 48 hours.
Attribution Assessment
MSTIC attributes this activity to Storm-1175 with high confidence. While the group's origins remain under investigation, their tactics, techniques, and procedures (TTPs) align with sophisticated Eastern European cybercriminal syndicates. There is no current evidence linking them to a specific nation-state, though their technical proficiency is on par with advanced persistent threats (APTs). The group's ability to rapidly weaponize N-day vulnerabilities suggests they possess significant resources and a dedicated research and development arm.
Implications
The emergence of StormEncryptor highlights the persistent risk to the MSP ecosystem. Successful exploitation leads to widespread operational paralysis across multiple industries, including healthcare and finance. The use of Rust-based malware suggests a trend toward cross-platform capabilities, potentially threatening Linux-based server environments in future iterations. Furthermore, the targeting of MSPs creates a trust deficit between service providers and their clients, which could lead to long-term shifts in how organizations manage their IT infrastructure and security outsourcing.
Recommendations
Organizations using N-able solutions must immediately apply the latest security patches to mitigate CVE-2026-33012. Additionally, MSPs should implement strict network segmentation between their management infrastructure and client environments. Enabling multi-factor authentication (MFA) across all administrative portals and maintaining offline, immutable backups are critical steps to mitigate the impact of a StormEncryptor infection. We also recommend that security teams update their EDR signatures to include the latest indicators of compromise (IOCs) associated with the Storm-1175 PowerShell loader and the StormEncryptor binary.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Professional and Healthcare Sectors

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

