China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Reported exploitedStormEncryptorStorm-1175N-centralOur summary
Microsoft has identified that the China-linked threat actor Storm-1175 is actively deploying a new ransomware variant called StormEncryptor, likely leveraging the recently disclosed authentication bypass vulnerability CVE-2026-18577 in N-able N-central. This attack marks a tactical shift for the group, which had previously relied on the Medusa ransomware family, and involves the use of remote management tools like AnyDesk and SimpleHelp alongside Mimikatz for credential theft. CISA has flagged the underlying vulnerabilities as being actively exploited, urging organizations to immediately apply available patches to prevent rapid compromise and data exfiltration.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.