INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

| 2026-08-13 08:09 CRITICAL HIGH
Executive Summary AI-generated
The threat actor, Storm-1175, has begun using a new ransomware strain called StormEncryptor in its latest attacks. This marks an evolution in the group's tactics as they exploit newly disclosed vulnerabilities before organizations can patch them. The attackers' speed and efficiency are highlighted by their ability to deploy ransomware in as little as one day, targeting sectors such as healthcare, education, finance, and services across the US, UK, and Australia. Microsoft has confirmed that China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa with this latest threat. The group's use of tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for remote access, Advanced IP Scanner to map networks, and LSASS credentials dumping suggests their sophistication in exploiting vulnerabilities. This incident data indicates a growing concern as the attackers continue to adapt and exploit newly disclosed vulnerabilities, necessitating rapid patching and monitoring to prevent further attacks.
Technical Mitigations AI-generated
* Implement a patching policy for all vulnerable systems and software as soon as possible to prevent exploitation of newly disclosed vulnerabilities. * Conduct regular security audits and vulnerability assessments to identify potential entry points for attackers, and prioritize remediation efforts accordingly. * Use multi-factor authentication (MFA) whenever possible to reduce the attack surface and make it more difficult for attackers to gain initial access. * Implement a secure remote management (RMM) tool or software that can detect and respond to ransomware attacks in real-time, such as PDQ Deployer or Impacket. * Monitor network traffic and system logs closely for signs of suspicious activity, and have incident response plans in place to quickly contain and mitigate ransomware infections.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2023-37679CVE-2023-37679 CVE-2025-10035CVE-2025-10035 CVE-2024-27199CVE-2024-27199 CVE-2024-27198CVE-2024-27198 CVE-2026-18577CVE-2026-18577 CVE-2023-43208CVE-2023-43208 CVE-2026-18556CVE-2026-18556 CVE-2024-1708CVE-2024-1708 CVE-2023-48788CVE-2023-48788 CVE-2024-1709CVE-2024-1709
Target & Sectors
NORTH_AMERICA NORTH_AMERICA financefinance educationeducation healthcarehealthcare
Incident Timeline
‎October 2025
Threat actors used Fortra GoAnywhere to exploit CVE-2025-10035, a critical security vulnerability.
tactic Ransomware
vulnerability CVE-2025-10035
organisation Fortra GoAnywhere
‎April 2026
Storm-1175 deployed StormEncryptor, a new ransomware.
tactic Ransomware
attribution Microsoft Threat Intelligence
attribution Microsoft
‎August 2, 2026
Threat actors used CVE-2026-18577 authentication bypass vulnerability in N-able to target StormEncryptor ransomware.
tactic Ransomware
vulnerability CVE-2026-18577
tactic T1588.006 - Vulnerabilities
attribution KEV
‎August 2
Threat actors used a previously unknown vulnerability (CVE-2026-18577) in StormEncryptor ransomware to gain access.
vulnerability CVE-2026-18577
infrastructure 2026.3
infrastructure 2026.3.1
organisation CVE-2026
general_metric 2026.3 HF1
‎August 3, 2026
Microsoft confirmed the incident through Microsoft on August 13, 2026.
tactic Ransomware
vulnerability CVE-2026-18577
tactic T1588.006 - Vulnerabilities
attribution KEV
‎Aug 10, 2026
Threat actors used StormEncryptor ransomware to target a previously compromised Medusa affiliate.
‎2026/08/13
Storm-1175 used a newly disclosed security flaw in N-central to obtain initial access.
organisation Microsoft
organisation Storm-1175
organisation StormEncryptor
organisation Ransomware / Cybercrime
organisation Microsoft Exchange
infrastructure Smartermail
organisation MFT
organisation Invanti Connect Secure
organisation JetBrains TeamCity
organisation CVE-2023-43208
organisation CVE-2023-48788
organisation ConnectWise ScreenConnect
organisation Fortinet FortiClient EMS
organisation AnyDesk
organisation SimpleHelp
organisation Advanced IP Scanner
organisation the Local Security Authority Subsystem Service
organisation SecurityAffairs
organisation Ivanti
organisation ConnectWise
organisation JetBrains
infrastructure Windows
infrastructure Linux
organisation PsExec
organisation RDP
organisation Cloudflare
organisation RMM
organisation PDQ Deployer
organisation Cloudflared
organisation IP
organisation EDR
Tactical Metrics
Metrics
infrastructure
‎Ivanti
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Smartermail
Affected Product
Metrics
infrastructure
‎2026.3
Software Version
Metrics
infrastructure
‎2026.3.1
Software Version
Intelligence Sources