bleeping-computer · Crawled Aug 10, 2026
New StormEncryptor ransomware used by former Medusa affiliate
8 IoCs 1 Actors
Read original article ↗
AI Summary
A China-based threat actor tracked as Storm-1175, previously associated with the Medusa ransomware operation, has shifted to using a new ransomware variant called StormEncryptor. The actor exploits a vulnerability in the N-central RMM tool (CVE-2026-18577) to gain initial access, then uses tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for lateral movement and credential dumping. StormEncryptor is written in C++, encrypts files appending the '.encrypted' extension, and drops a ransom note titled '!!!README_FIRST!!!.txt', threatening data leakage if payment is not negotiated within three days.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 8 extracted
MITRE ATT&CK TTPs 8 techniques
T1003.001 LSASS Memory · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1074 Data Staged · Collection T1078 Valid Accounts · Defense Evasion T1486 Data Encrypted for Impact · Impact