Threat Actor 🇨🇳 China

Storm-1175

Storm-1175 is a cybercriminal group known for deploying Medusa ransomware and exploiting public-facing applications for initial access. They have been observed exploiting a critical deserialization vulnerability in GoAnywhere MFT, tracked as CVE-2025-10035, which could lead to command injection and potential RCE. Microsoft Defender researchers identified exploitation activity aligned with TTPs attributed to Storm-1175, including the use of post-compromise techniques that involve creating a group named “ESX Admins” in the domain.

Indicators of Compromise 8

MITRE ATT&CK TTPs 8

Source Articles

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Storm-1175, a China-linked financially motivated threat actor, has deployed a new ransomware named StormEncryptor, written in C++, which appends the '.encrypted' extension to encrypted files and drops a ransom note titled '!!!README_FIRST!!!.txt'. The group likely gained initial access by exploiting CVE-2026-18577, a patch bypass vulnerability in N-able N-central, which allows authentication bypass and account takeover. Storm-1175 has a history of exploiting vulnerabilities in internet-facing systems, rapidly moving from initial access to data exfiltration and ransomware deployment within days, using tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for credential dumping.
hacker-news ·4h ago
New StormEncryptor ransomware used by former Medusa affiliate
A China-based threat actor tracked as Storm-1175, previously associated with the Medusa ransomware operation, has shifted to using a new ransomware variant called StormEncryptor. The actor exploits a vulnerability in the N-central RMM tool (CVE-2026-18577) to gain initial access, then uses tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for lateral movement and credential dumping. StormEncryptor is written in C++, encrypts files appending the '.encrypted' extension, and drops a ransom note titled '!!!README_FIRST!!!.txt', threatening data leakage if payment is not negotiated within three days.
bleeping-computer ·2h ago