StormEncryptor is a C++ ransomware family deployed by the financially motivated, China-linked threat actor Storm-1175 beginning in August 2026, marking a shift from the actor's earlier association with Medusa ransomware. It encrypts files, appends an encryption-related extension, and places ransom notes in scanned directories. Its extortion model combines payment demands with threats to publish stolen data if negotiations do not occur within three days. Storm-1175 operations associated with StormEncryptor likely obtained access through exploitation of an authentication-bypass vulnerability affecting N-able N-central, a remote monitoring and management platform. Compromise of such infrastructure can expose both managed service providers and downstream customer environments. Associated intrusions have involved remote-access software, network discovery, credential dumping from LSASS, lateral movement, data theft, and rapid ransomware deployment, sometimes within 24 hours of initial compromise. Storm-1175 has principally targeted healthcare, education, finance, and professional-services organizations in the United States, United Kingdom, and Australia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft says that Storm-1175 most likely used a publicly known zero-day vulnerability, CVE-2026-18577, to gain unauthorized access to N-central. N-able identified active exploitation on July 31; its first patch was ineffective, and it later issued two additional emergency patches. The vulnerability has a CVSS score of 8.2 and was added to CISA's Known Exploited Vulnerabilities catalog on August 3. | Storm-1175 started deploying C++ StormEncryptor ransomware on August 2... Storm-1175 ransomware encrypts files and demands payment, threatening to release the data within three days.
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. "StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts," Microsoft noted.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft observed Storm-1175 deploying a new ransomware strain of its own, StormEncryptor, rather than Medusa.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Security researchers reported attackers exploiting the vulnerability to obtain highly privileged access and subsequently conduct reconnaissance and lateral movement across affected environments.
Look for AnyDesk, SimpleHelp, unexpected services, scheduled tasks, renamed tunneling tools, PowerShell abuse and antivirus exclusions.
Look for AnyDesk, SimpleHelp, unexpected services, scheduled tasks, renamed tunneling tools, PowerShell abuse and antivirus exclusions.
Look for AnyDesk, SimpleHelp, unexpected services, scheduled tasks, renamed tunneling tools, PowerShell abuse and antivirus exclusions.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate ransomware strain deployed by Storm-1175 as of August 2026, potentially indicating the actor is moving away from Medusa.
C++ ransomware deployed by Storm-1175 that encrypts files, demands payment, and threatens to publish stolen data within three days. The group used it after exploiting the N-central authentication-bypass zero-day to access managed-service environments and downstream organizations.
A ransomware strain written in C++ that encrypts files, appends the .encrypted extension, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory.
An earlier undocumented ransomware strain installed by Storm-1175 in high-velocity campaigns, with Microsoft observing rapid progression from initial access to full encryption in less than 24 hours.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.