Former Medusa Affiliate Deploys New StormEncryptor Ransomware

A China-linked threat actor tracked as Storm-1175, previously associated with Medusa ransomware, has shifted to deploying a new encryptor called StormEncryptor after a four-month hiatus. The group likely gained initial access through exploitation of an authentication bypass vulnerability in N-central remote monitoring and management software. StormEncryptor appends encrypted files with the .encrypted extension and drops ransom notes demanding payment within three days to prevent data leaks.

The attackers used tools including AnyDesk and SimpleHelp for remote access, Advanced IP Scanner for network discovery, and Mimikatz for credential dumping from LSASS. Microsoft warns that Storm-1175 typically completes data exfiltration and ransomware deployment within days of compromise. N-able released a hotfix for the vulnerability on August 2 and urges immediate patching, while recommending organizations monitor for suspicious svchost.exe activity and Cloudflared services. The threat actor previously exploited vulnerabilities in products including GoAnywhere MFT, Microsoft Exchange, and JetBrains TeamCity. The shift away from Medusa marks the group's first observed activity since April 2026, signaling a potential evolution in their operational tactics. System administrators managing self-hosted N-central servers are advised to apply security patches immediately and check for signs of compromise.

Read more...

Read More

Got Something To Say?

Your email address will not be published.