bleeping-computer · Crawled Aug 10, 2026

New StormEncryptor ransomware used by former Medusa affiliate

8 IoCs 1 Actors
Read original article ↗

AI Summary

A China-based threat actor tracked as Storm-1175, previously associated with the Medusa ransomware operation, has shifted to using a new ransomware variant called StormEncryptor. The actor exploits a vulnerability in the N-central RMM tool (CVE-2026-18577) to gain initial access, then uses tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for lateral movement and credential dumping. StormEncryptor is written in C++, encrypts files appending the '.encrypted' extension, and drops a ransom note titled '!!!README_FIRST!!!.txt', threatening data leakage if payment is not negotiated within three days.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 8 extracted

Type Value Detail
Filename !!!README_FIRST!!!.txt Details →
Filename svchost.exe Details →
Domain cloudflared Details →
IP 185[.]187[.]13[.]137 Details →
IP 45[.]147[.]229[.]137 Details →
IP 45[.]147[.]229[.]138 Details →
IP 45[.]147[.]229[.]139 Details →
IP 45[.]147[.]229[.]140 Details →

MITRE ATT&CK TTPs 8 techniques