Exploited in the wild StormEncryptor Storm-1175 ransomware N-central Microsoft
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
CVE Tools coverage
Microsoft has identified that the China-linked threat actor Storm-1175 is actively deploying a new ransomware variant called StormEncryptor, likely leveraging the recently disclosed authentication bypass vulnerability CVE-2026-18577 in N-able N-central. This attack marks a tactical shift for the group, which had previously relied on the Medusa ransomware family, and involves the use of remote management tools like AnyDesk and SimpleHelp alongside Mimikatz for credential theft. CISA has flagged the underlying vulnerabilities as being actively exploited, urging organizations to immediately apply available patches to prevent rapid compromise and data exfiltration.