Storm-1175 Returns With New StormEncryptor Ransomware & Fresh Attack Tactics, Microsoft Warns
Storm-1175 is back, and Microsoft says the ransomware crew has switched things up with a new strain called StormEncryptor. In a detailed post on X, Microsoft Threat Intelligence shared that the financially motivated group started deploying the malware on August 2, marking its first activity observed by Microsoft since April.
Storm-1175 has moved beyond Medusa
StormEncryptor represents a notable change for the group. Storm-1175 was previously associated with fast-moving Medusa ransomware campaigns. The new ransomware is written in C++ and adds the .encrypted extension to targeted files. It also drops a !!!README_FIRST!!!.txt ransom note inside scanned directories.
Microsoft has not confirmed exactly how Storm-1175 gained access during this campaign. However, the company believes the actor may be exploiting CVE-2026-18577. The vulnerability affects N-able and involves an authentication bypass. It was disclosed on August 2 and reportedly entered CISA’s Known Exploited Vulnerabilities catalog the following day.
Microsoft has previously described Storm-1175 as an actor that quickly weaponizes newly disclosed vulnerabilities.
The ransomware attacks are moving fast
Once inside a network, Storm-1175 reportedly relies on familiar administration tools for its operations. Microsoft observed the group using AnyDesk and SimpleHelp for remote access. It also uses Advanced IP Scanner for network discovery.
Credential theft is another part of the activity. Microsoft says Storm-1175 has used Mimikatz alongside LSASS dumping techniques. The group is known for moving quickly from initial access toward data theft and ransomware deployment. Microsoft previously observed some attacks reaching ransomware deployment within a day.
Microsoft Defender Antivirus detects StormEncryptor as Ransom:Win64/StormEncryptor. Defender for Endpoint also provides alerts tied to hands-on-keyboard attacks and potential human-operated malicious activity.
Organizations should prioritize patching exposed systems and watching for unusual remote-management activity.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages