securityaffairs.com 8/13/2026, 8:51:36 AM · external

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Developing story vulnerability 11 articles tracked
CISA adds three actively exploited flaws to KEV catalog
CyberSIXT Evidence Panel
Primary Source microsoft.com
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
🇨🇳 Storm-1175

MICROSOFT has reported that the China-linked cybercriminal group Storm-1175 has replaced its previous ransomware, Medusa, with a new strain known as StormEncryptor. This ransomware encrypts files and appends a `.encrypted` extension, along with leaving a ransom note in affected directories. Storm-1175 exploits vulnerabilities, particularly targeting a described CVE-2026-18577 in N-able, previously undisclosed.

The group is known for its rapid attacks, often moving from initial access to data theft and ransom within days, using tools like AnyDesk and Mimikatz. With a focus on vulnerable systems in sectors such as healthcare and finance across the US, UK, and Australia, Storm-1175 has been able to maximize its effectiveness by quickly deploying ransomware and leveraging newly disclosed flaws.

In its operations, the group has exploited over 16 vulnerabilities in prominent platforms since 2023, demonstrating advanced capabilities, including exploiting zero-day vulnerabilities before they are publicly acknowledged.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline