Microsoft Threat Intelligence has observed the financially motivated threat actor Storm-1175 deploying a previously unseen ransomware family, dubbed StormEncryptor, beginning August 2, 2026.
The activity represents the group’s first publicly observed campaign since April and signals a departure from Medusa ransomware, which Storm-1175 had previously used in extortion operations.
The campaign may be tied to the rapid weaponization of CVE-2026-18577, an authentication-bypass vulnerability affecting N-able products.
Storm-1175 Deploys New StormEncryptor Ransomware
Although Microsoft has not confirmed the initial access vector, the timing strongly suggests that Storm-1175 is exploiting the newly disclosed flaw to compromise exposed environments before organizations can complete patching.
StormEncryptor is a C++-based ransomware payload that encrypts files and appends the .encrypted extension to affected filenames. Following encryption, the malware creates a ransom note named !!!README_FIRST!!!.txt in every scanned directory, instructing victims to contact the attackers through anonymity-focused communication channels.
The note warns against attempting independent recovery and threatens publication of stolen data if victims do not engage within three days.
Microsoft Defender Antivirus detects the identified StormEncryptor sample SHA-256 c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054 as Ransom:Win64/StormEncryptor.
Defender for Endpoint can also identify associated hands-on-keyboard behavior through alerts including “Hands-on-keyboard attack involving multiple devices” and “Potential human-operated malicious activity.”
CVE-2026-18577 was disclosed on August 2 and added to CISA’s Known Exploited Vulnerabilities catalog on August 3, underscoring evidence of active exploitation.
The suspected use of the flaw fits Storm-1175’s established operating model: rapidly exploiting newly disclosed vulnerabilities, or N-days, between public disclosure and widespread patch deployment.
Organizations that delay remediation of internet-facing remote management infrastructure can inadvertently provide attackers with privileged access, opportunities for persistence, and a path to connected customer or enterprise systems.
Following initial access, Storm-1175 has been observed abusing legitimate remote monitoring and management tools, including AnyDesk and SimpleHelp.
Such tools can help operators blend malicious remote access with routine administrative activity, while reducing the need to deploy conspicuous custom backdoors.
The group also uses Advanced IP Scanner to enumerate internal systems and identify high-value targets. Credential-access activity includes dumping the Local Security Authority Subsystem Service process with Mimikatz, enabling attackers to obtain credentials and potentially expand across a victim’s network.
This sequence of initial access, discovery, credential theft, lateral movement, data theft, and encryption is consistent with human-operated ransomware operations.
Microsoft assesses that Storm-1175 can move from compromise to exfiltration and ransomware deployment within only a few days, leaving defenders little time to contain an intrusion.
Mitigation
Organizations using N-able products should prioritize applying vendor security updates addressing CVE-2026-18577 and verify that internet-facing management interfaces are necessary, restricted, and strongly authenticated.
Security teams should investigate unexpected deployment or use of AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz-related artifacts.
Defenders should also monitor for files ending in .encrypted, the creation of !!!README_FIRST!!!.txt, suspicious LSASS access, unusual credential use, and rapid lateral movement across endpoints.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR
Click Here For The Original Source.
