News Room
16
Share
Storm-1175 Shifts to Custom StormEncryptor Ransomware in Rapid Exploitation Campaigns
highThreat Intelligence

Storm-1175 Shifts to Custom StormEncryptor Ransomware in Rapid Exploitation Campaigns

Microsoft Threat Intelligence has identified China-linked actor Storm-1175 adopting the proprietary StormEncryptor payload, abandoning Medusa in high-tempo initial access operations.

04 September 2026Last updated 04 September 20263 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-1731, CVE-2023-27350, CVE-2023-27351
Source:
Microsoft MSTIC
Read Time:
3 min

Executive Summary

Recent intelligence disclosed by Security Affairs: Storm-1175 Replaces Medusa With New StormEncryptor Ransomware reveals that the prolific cybercriminal actor tracked as Storm-1175 has formally integrated a custom encryption toolchain dubbed StormEncryptor. Known for weaponizing zero-day and n-day vulnerabilities within hours of public disclosure, the group has deprecated its prior reliance on Medusa ransomware in favor of an in-house encryptor designed to bypass modern endpoint detection controls while maintaining rapid operational tempo.

Threat Analysis

Storm-1175 maintains an aggressive operational cycle that blurs the boundaries between advanced persistent threats (APTs) and financially motivated ransomware groups. Rather than operating strictly under a standard Ransomware-as-a-Service (RaaS) affiliate model, the group relies heavily on direct exploitation of internet-facing enterprise services, followed immediately by rapid credential theft and environment-wide ransomware deployment within a matter of days.

Technical Details

  • Initial Access: Weaponization of edge appliance and remote management vulnerabilities, including BeyondTrust (CVE-2026-1731), PaperCut (CVE-2023-27350, CVE-2023-27351), and Exchange infrastructure.
  • Discovery & Reconnaissance: Network mapping executed via Advanced IP Scanner alongside internal probing scripts.
  • Credential Access: Automated dumping of the Local Security Authority Subsystem Service (lsass.exe) process via custom Mimikatz implementations.
  • Command and Control: Deployment of commercial remote desktop software, specifically AnyDesk and SimpleHelp, to evade heuristic traffic baselines.
  • Execution: Execution of StormEncryptor, a high-performance multithreaded encryptor utilizing hybrid symmetric/asymmetric cryptographic routines and anti-recovery measures targeting Windows Volume Shadow Copies.

Attribution Assessment

Microsoft Threat Intelligence has attributed this activity to Storm-1175, characterized as an advanced, financially motivated actor with regional and operational ties to China. While their primary objective remains monetary extortion, their tooling efficiency and swift exploitation cadence parallel elite nation-state reconnaissance teams.

Implications

The transition to StormEncryptor indicates that threat groups are increasingly abandoning shared RaaS payloads to avoid signature-based global telemetry traps. With average dwell times compressing below 48 hours from edge breach to encryption, reactive mitigation strategies are insufficient against Storm-1175.

Recommendations

  1. Edge Perimeter Hardening: Enforce immediate patch cadence on public-facing assets, specifically remote management systems, mail relays, and authentication gateways.
  2. RMM Tool Policy Enforcement: Block unauthorized execution of commercial tools like AnyDesk, SimpleHelp, and unauthorized IP scanners across production subnets.
  3. LSASS Protection: Enforce RunAsPPL and Credential Guard to prevent memory dumping vectors.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo