A former Medusa affiliate has launched the StormEncryptor ransomware, exploiting CVE‑2026‑18577 in N‑central RMM tools. Victims receive a three‑day ransom deadline before data is leaked online.

Key Takeaways

  • Storm‑1175 releases new StormEncryptor ransomware
  • Exploits vulnerability CVE‑2026‑18577 in N‑central
  • Three‑day ransom deadline with threat of data leak

New Threat Emerges

Microsoft Threat Intelligence identifies a China‑based actor, Storm‑1175, previously linked to the Medusa ransomware operation. The group now deploys StormEncryptor, a C++ ransomware that appends “.encrypted” to compromised files and drops a ransom note named ‘!!!README_FIRST!!!.txt’ in every scanned directory.

The note gives victims three days to negotiate payment; otherwise the stolen data will be published online. After initial access, the attacker uses AnyDesk or SimpleHelp for remote control, Advanced IP Scanner for network discovery, and Mimikatz to dump credentials from LSASS.

Historical Background

The Medusa ransomware gang was active from 2023 to 2025, targeting platforms such as GoAnywhere MFT, SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity. Their tactics involved rapid data exfiltration followed by ransomware deployment, forcing organizations into rushed negotiations.

Why This Matters

BozokMedia analysis shows that the shift from Medusa’s ransomware to the more aggressive StormEncryptor signals a strategic escalation, targeting organizations that rely on self‑hosted N‑central servers. The rapid pivot underscores the need for immediate patching and continuous monitoring of remote management tools.

"Storm‑1175’s use of CVE‑2026‑18577 demonstrates how legacy RMM vulnerabilities remain a lucrative attack vector for sophisticated ransomware groups," said Dr. Ananya Rao, cybersecurity researcher.

Did You Know?

Did You Know?: Over 18 % of enterprises running older N‑central versions ignored similar remote‑access vulnerabilities between 2022‑2024.

Frequently Asked Questions

  • Is there a specific patch to stop StormEncryptor? Yes, N‑able released hotfix 2026.3 HF1 on August 2 to remediate CVE‑2026‑18577; immediate deployment is recommended.
  • Can outdated AnyDesk or SimpleHelp installations be compromised? Absolutely; without recent security updates, these tools can serve as entry points for attackers.