Threat Actor 🇨🇳 China
Storm-1175
Storm-1175 is a cybercriminal group known for deploying Medusa ransomware and exploiting public-facing applications for initial access. They have been observed exploiting a critical deserialization vulnerability in GoAnywhere MFT, tracked as CVE-2025-10035, which could lead to command injection and potential RCE. Microsoft Defender researchers identified exploitation activity aligned with TTPs attributed to Storm-1175, including the use of post-compromise techniques that involve creating a group named “ESX Admins” in the domain.
Indicators of Compromise 8
MITRE ATT&CK TTPs 8
T1003.001 T1021.001 T1046 T1055 T1059.001 T1074 T1078 T1486
LSASS Memory
Credential Access
Remote Desktop Protocol
Lateral Movement
Network Service Discovery
Discovery
Process Injection
Defense Evasion
PowerShell
Execution
Data Staged
Collection
Valid Accounts
Defense Evasion
Data Encrypted for Impact
Impact
Source Articles
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Storm-1175, a China-linked financially motivated threat actor, has deployed a new ransomware named StormEncryptor, written in C++, which appends the '.encrypted' extension to encrypted files and drops a ransom note titled '!!!README_FIRST!!!.txt'. The group likely gained initial access by exploiting CVE-2026-18577, a patch bypass vulnerability in N-able N-central, which allows authentication bypass and account takeover. Storm-1175 has a history of exploiting vulnerabilities in internet-facing systems, rapidly moving from initial access to data exfiltration and ransomware deployment within days, using tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for credential dumping.
hacker-news ·4h ago
New StormEncryptor ransomware used by former Medusa affiliate
A China-based threat actor tracked as Storm-1175, previously associated with the Medusa ransomware operation, has shifted to using a new ransomware variant called StormEncryptor. The actor exploits a vulnerability in the N-central RMM tool (CVE-2026-18577) to gain initial access, then uses tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for lateral movement and credential dumping. StormEncryptor is written in C++, encrypts files appending the '.encrypted' extension, and drops a ransom note titled '!!!README_FIRST!!!.txt', threatening data leakage if payment is not negotiated within three days.
bleeping-computer ·2h ago