Published Security3 min read
Storm-1175 drops Medusa for its own encryptor, and probably came in through N-able
Microsoft says the China-based crew has switched to a strain called StormEncryptor and is likely exploiting an N-able authentication bypass that CISA flagged one day after disclosure.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor.
- Storm-1175 previously relied on Medusa ransomware.
- Storm-1175 is described as a China-based, financially motivated group that carries out fast ransomware attacks by exploiting newly disclosed vulnerabilities before organizations patch them.
- Microsoft has not confirmed which vulnerability Storm-1175 targeted in this campaign.
- Microsoft wrote that the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Microsoft says Storm-1175, a China-based, financially motivated group, has stopped using Medusa ransomware and started deploying a new strain called StormEncryptor [1][2][3]. In the same statement on X, Microsoft said it has not confirmed which vulnerability the campaign is exploiting but that the actor is likely abusing CVE-2026-18577, an authentication bypass in N-able disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day [4][5][6][1].
The payload is ordinary, which is the useful part. StormEncryptor is written in C++, appends the .encrypted extension, and drops a !!!README_FIRST!!!.txt note in each directory it scans [7]. Microsoft describes the change as an evolution in the group's ransomware operations [8]. For defenders, the practical consequence is narrower and duller: detection content keyed to Medusa file artifacts does not describe this binary, so anyone who treated "Medusa" as the unit of coverage now has a gap [2].
The timing is the story. Microsoft says Storm-1175 often weaponizes newly disclosed flaws within days or even a single day, before patches are applied, and has used zero-days ahead of public disclosure [9][10]. It also says the group can move from initial access to data theft and ransomware deployment within days, sometimes within 24 hours [11]. Set that against a KEV listing that arrived one day after disclosure, and the interval that a maintenance window is supposed to fit into is at most as long as the group's own weaponization time [1][3].
The tradecraft is off the shelf. Microsoft reports recent use of AnyDesk and SimpleHelp for remote access, Advanced IP Scanner for network mapping, and Mimikatz to dump LSASS credentials [12]. After access, the group installs web shells or remote tools, creates administrator accounts for persistence, and moves laterally with PowerShell, PsExec, RDP and Cloudflare tunnels, while abusing legitimate RMM software along with PDQ Deployer and Impacket [13]. Since 2023, Microsoft says it has observed the group exploit more than 16 vulnerabilities across platforms including Microsoft Exchange, Ivanti, ConnectWise and JetBrains, on both Windows and Linux [14][15].
That target list is the pattern worth naming. N-able, ConnectWise and SimpleHelp all sit in the remote monitoring and management layer, which means one authentication bypass can convert into administrative reach across every downstream estate a provider touches [4]. Microsoft says the group mainly hits healthcare, education, finance and services in the United States, United Kingdom and Australia [16], sectors where the managed-provider model is the norm rather than the exception.
Worth tracking: whether Microsoft moves the N-able attribution from likely to confirmed [4], whether StormEncryptor shows up under other operators, and whether the vendor and CISA publish the exposure count for unpatched N-able instances. If you run N-able or resell through someone who does, the patch state of that server is the question, not the ransom note.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor.
- [2]
Storm-1175 previously relied on Medusa ransomware.
- [3]
Storm-1175 is described as a China-based, financially motivated group that carries out fast ransomware attacks by exploiting newly disclosed vulnerabilities before organizations patch them.
- [4]
Microsoft has not confirmed which vulnerability Storm-1175 targeted in this campaign.
- [5]
Microsoft wrote that the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able.
- [6]
CVE-2026-18577 was disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog on August 3, 2026.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi PaganiniAug 13Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Additional citations
- Microsoft, via SecurityAffairs
- Microsoft post on X, quoted by SecurityAffairs
- Microsoft Threat Intelligence report, via SecurityAffairs



