New Threat from China: Microsoft Warns of Storm-1175 Ransomware Group
Microsoft has revealed the activities of a financially motivated Chinese threat actor, Storm-1175, which is spreading a newly documented ransomware strain called StormEncryptor. The Microsoft Threat Intelligence team noted that the use of StormEncryptor marks a strategic shift for the group, which was previously active in deploying Medusa ransomware.
Written in C++, StormEncryptor appends the extension ‘.encrypted’ to compromised files. After encrypting target files, the group leaves a ransom note titled !!!README_FIRST!!!.txt in every scanned directory. While the primary security flaw exploited in these attacks has not been fully confirmed, Microsoft strongly suspects the actors are leveraging CVE-2026-18577. This vulnerability is a patch bypass for CVE-2026-18556 in N-able N-central software, allowing attackers to bypass authentication and fully take over accounts on vulnerable systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already added this vulnerability to its list of actively exploited flaws.
Storm-1175 is known for exploiting vulnerabilities in popular systems such as Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, and Fortinet FortiClient EMS. A previous analysis from October 2025 also mapped the group’s involvement in exploiting a critical Fortra GoAnywhere vulnerability (CVE-2025-10035) to facilitate Medusa attacks. Microsoft stated that the group weaponises a combination of zero-day and N-day exploits to launch rapid attacks, capitalising on the window between vulnerability disclosure and user patching to breach internet-connected systems. Post-compromise activities include the abuse of remote monitoring and management tools like AnyDesk or SimpleHelp, the use of Advanced IP Scanner for network scanning, and credential theft via LSASS dumping using Mimikatz. The entire attack chain, from initial access to data exfiltration and ransomware deployment, can occur within days. Microsoft urges all system administrators and customers to apply security patches immediately to mitigate the risk of compromise.