CVE Tools
Back to feed
Exploited in the wild StormEncryptor Storm-1175 ransomware N-central Microsoft

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Microsoft has identified that the China-linked threat actor Storm-1175 is actively deploying a new ransomware variant called StormEncryptor, likely leveraging the recently disclosed authentication bypass vulnerability CVE-2026-18577 in N-able N-central. This attack marks a tactical shift for the group, which had previously relied on the Medusa ransomware family, and involves the use of remote management tools like AnyDesk and SimpleHelp alongside Mimikatz for credential theft. CISA has flagged the underlying vulnerabilities as being actively exploited, urging organizations to immediately apply available patches to prevent rapid compromise and data exfiltration.