StormEncryptor Ransomware: China-linked Storm-1175's Rapid-Encryption Kit (N-able CVE-2026-18577)
On August 2, 2026, Microsoft Threat Intelligence observed the China-linked, financially motivated group Storm-1175 — previously associated with the Medusa ransomware ecosystem — start deploying a new C++ ransomware family it named StormEncryptor. The payload appends the .encrypted extension to victim files and drops a !!!README_FIRST!!!.txt ransom note on every encrypted directory. Microsoft assesses initial access likely came through CVE-2026-18577, the patch-bypass of the N-able N-central auth-bypass flaw CVE-2026-18556, both listed by CISA as actively exploited; Huntress and Sophos have confirmed intrusions against N-central customers. Post-compromise, Storm-1175 abuses AnyDesk and SimpleHelp for persistent remote access, runs Advanced IP Scanner for discovery, and dumps LSASS with Mimikatz — moving from access to exfiltration and encryption within days. This demo ships EICAR test files — a classic eicar.com, an eicar.txt, a compiled Windows PE embedding the EICAR string, and a ZIP-wrapped EICAR — standing in for the ransomware binary and staged payloads, plus a clean control file (no real malware, nothing destructive). MetaDefender Multiscan runs 30+ engines (including ClamAV) over every variant in one pass and flags them all, showing how an encryption campaign is stopped at the file boundary — at the gateway, before StormEncryptor ever touches a disk.
Attack Technique
Data encrypted for impact — ransomware deployed via exploited RMM auth-bypass (T1486)
MITRE ATT&CK
T1486 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗