> Back to All Posts

StormEncryptor Ransomware Linked to Ex-Medusa Affiliate

StormEncryptor Ransomware

A new ransomware strain has surfaced, and the group behind it already has a long track record. Microsoft Threat Intelligence has connected StormEncryptor ransomware to Storm-1175, a financially motivated actor that spent months working as an affiliate of the Medusa operation. The group appears to have cut ties with that brand and built its own locker instead. So far, the attacks trace back to a single unpatched flaw in a tool that IT teams rely on to manage other people’s networks.

What StormEncryptor ransomware does once it lands

The developers wrote the malware in C++, a common choice because it compiles into fast, self-contained binaries. Once it runs, StormEncryptor ransomware encrypts files and adds the .encrypted extension to each one. It then drops a ransom note titled !!!README_FIRST!!!.txt into every folder it scans, so victims cannot miss it.

The note sets a three day deadline for opening negotiations. Miss that window, and the attackers publish the stolen files instead. That threat points to double extortion, where criminals steal data first and encrypt it second. Backups still help with recovery, but they do nothing to stop a leak.

The N-central flaw behind the attacks

Microsoft believes the intrusions began with exploitation of CVE-2026-18577, an authentication bypass vulnerability in N-able N-central. The product is a remote monitoring and management platform, and managed service providers use it to oversee client machines at scale. An attacker who bypasses authentication there gains legitimate reach into many downstream systems at once. Every known StormEncryptor ransomware attack traces back to that entry point.

N-able released a hotfix on August 2, shipping as version 2026.3 HF1, build 2026.3.1.7. The company urged customers to apply it right away. Self-hosted servers carry the most risk, because patching depends entirely on the administrator rather than the vendor.

A former Medusa affiliate strikes out alone

Microsoft believes Storm-1175 operates from China, and researchers have documented its activity for years. The group previously deployed Medusa ransomware after exploiting zero-day and n-day flaws in GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Ivanti Connect Secure, and JetBrains TeamCity. Its method has stayed consistent: find an exposed enterprise application, break in through it, then monetize the access.

The switch away from Medusa matters because it signals independence. Affiliates rent a locker and hand over a cut of every payment, so an in-house tool removes both the fee and the dependency. StormEncryptor ransomware also gives the group a codebase nobody else uses, which slows down detection tools that rely on known families.

The toolkit used after initial access

After breaking in, the attackers install remote access software to hold their position. They have used AnyDesk and SimpleHelp, both legitimate products that security tools often allow by default. Advanced IP Scanner then maps the internal network, and Mimikatz pulls credentials straight from the LSASS process in Windows memory.

None of these tools are exotic, and that is exactly the point. Defenders struggle to flag software their own helpdesk teams use every day. Because the group can move from first access to StormEncryptor ransomware deployment within days, slow alert triage often arrives too late.

Signs of compromise worth checking now

N-able has published concrete indicators for administrators to hunt for. One is an svchost.exe file sitting inside a user’s Documents folder, which never happens on a healthy system. Another is a registered service named Cloudflared. A third is inbound traffic from the IP addresses listed in the vendor advisory.

Anyone running a self-hosted N-central instance should check for all three, even after patching. A hotfix closes the door, but it does not remove an intruder who already walked through it.

What StormEncryptor ransomware means for everyday users

Most people will never touch an N-central console. However, their personal data often sits inside systems managed through one. Dental practices, law firms, small retailers, and local councils all outsource IT, so one compromised provider can expose thousands of unrelated customers.

That is why the leak threat behind StormEncryptor ransomware carries weight far beyond the victim organization. Once criminals publish personal records, those files circulate through underground marketplaces and fuel phishing and identity fraud for years. Individuals cannot patch someone else’s server, but they can limit their exposure. Unique passwords, multi-factor authentication, and an encrypted connection on untrusted networks all reduce the damage a leak can do.

Final Thoughts

Storm-1175 has spent years proving that unpatched enterprise software is the easiest way into a network. StormEncryptor ransomware simply gives the group a fresh tool for a familiar playbook. The malware will change again, but the entry point rarely does.

Organizations that depend on remote management platforms should treat every advisory as urgent. Apply the N-central hotfix, hunt for the published indicators, and assume that any delay hands attackers the few days they need. Speed decides the outcome on both sides of this one.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.