
Storm-1175 Shifts Tactics: New 'StormEncryptor' Ransomware Targets N-able N-central Vulnerabilities
Financially motivated actor Storm-1175 has abandoned the Medusa ransomware strain in favor of a new, proprietary family dubbed StormEncryptor. The group is actively exploiting CVE-2026-18577 in N-able products.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-18577
- Source:
- Microsoft Threat Intelligence
- Read Time:
- 4 min
Executive Summary
Microsoft Threat Intelligence has identified a significant shift in the operations of the financially motivated threat actor Storm-1175. As of August 2, 2026, the group has transitioned away from the Medusa ransomware, which served as their primary extortion tool, to a newly developed ransomware family identified as 'StormEncryptor'. This pivot coincides with the group's aggressive exploitation of a critical authentication-bypass vulnerability, CVE-2026-18577, affecting N-able N-central remote monitoring and management (RMM) software.
Threat Analysis
Storm-1175 is characterized by its high operational tempo and ability to weaponize newly disclosed vulnerabilities within days of their public release. By targeting RMM platforms, the group gains immediate, high-privilege access to the downstream networks of managed service providers (MSPs) and their clients. The transition to StormEncryptor suggests a desire for greater control over the encryption process and potentially a move to evade signature-based detection systems that were previously tuned to identify Medusa-related artifacts.
Technical Details
In recent campaigns, Storm-1175 has demonstrated a consistent post-exploitation playbook. Upon gaining initial access via the N-able N-central flaw, the actors deploy legitimate remote access tools such as AnyDesk and SimpleHelp to maintain persistence. Network reconnaissance is conducted using Advanced IP Scanner, followed by the use of Mimikatz to harvest credentials from the Local Security Authority Subsystem Service (LSASS). The StormEncryptor payload is then distributed across the environment. The speed of this progression—often moving from initial access to data exfiltration and encryption within a few days—underscores the critical nature of the threat.
Attribution Assessment
Microsoft Threat Intelligence attributes this activity to Storm-1175, a group known for its focus on rapid monetization through ransomware. While the group has previously utilized third-party ransomware-as-a-service (RaaS) models, the development of StormEncryptor indicates a potential move toward a more self-sufficient, vertically integrated criminal operation.
Implications
Organizations utilizing N-able N-central are at immediate risk. The ability of Storm-1175 to bypass authentication mechanisms allows them to bypass traditional perimeter defenses. The shift to a custom ransomware strain also complicates incident response, as security teams may lack established decryption tools or specific indicators of compromise (IOCs) for the new family.
Recommendations
- Immediate Patching: Ensure all N-able N-central instances are updated to the latest version to mitigate CVE-2026-18577.
- Enhanced Monitoring: Implement strict monitoring for the use of remote access tools like AnyDesk and SimpleHelp in environments where they are not standard.
- Credential Hygiene: Enforce multi-factor authentication (MFA) across all administrative interfaces and restrict access to RMM consoles to known, trusted IP addresses.
- Threat Hunting: Search for unauthorized use of network scanning tools and LSASS memory dumping activities.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Secp0 and Qilin Ransomware Groups Escalate Global Attacks on Real Estate and Electronics Sectors

Ransomware Surge: Record 1,073 Victims in August 2026 as ShinyHunters Targets Rival Clop Gang

