hacker-news · Crawled Aug 10, 2026
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
1 IoCs 1 Actors 2 CVEs
Read original article ↗
AI Summary
Storm-1175, a China-linked financially motivated threat actor, has deployed a new ransomware named StormEncryptor, written in C++, which appends the '.encrypted' extension to encrypted files and drops a ransom note titled '!!!README_FIRST!!!.txt'. The group likely gained initial access by exploiting CVE-2026-18577, a patch bypass vulnerability in N-able N-central, which allows authentication bypass and account takeover. Storm-1175 has a history of exploiting vulnerabilities in internet-facing systems, rapidly moving from initial access to data exfiltration and ransomware deployment within days, using tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for credential dumping.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | !!!README_FIRST!!!.txt | Details → |
MITRE ATT&CK TTPs 8 techniques
T1003.001 LSASS Memory · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1074 Data Staged · Collection T1078 Valid Accounts · Defense Evasion T1486 Data Encrypted for Impact · Impact