5 min read

A Familiar Hand, A New Weapon: Storm-1175 Steps Out From Medusa's Shadow- 308

A Familiar Hand, A New Weapon: Storm-1175 Steps Out From Medusa's Shadow- 308

August 11, 2026

A ransomware group going quiet for four months usually means one of two things: law enforcement caught up with it, or it's retooling. Microsoft's threat intelligence team says the answer for Storm-1175, a financially motivated, China-based actor last seen in April 2026, was the second — and what it came back with in August is not a new alias for old tools, but a proprietary ransomware strain deployed through one of the most efficient distribution channels available to any criminal group: a single compromised piece of remote-management software sitting between an attacker and every network that software administers.

Storm-1175 did not arrive at this point untested. Prior to its spring disappearance, Microsoft had tracked the group as a Medusa ransomware affiliate running what the company describes as high-velocity campaigns against finance, healthcare, and professional-services organizations across the US, Australia, and the UK, built on a specific and fairly aggressive pattern: exploiting zero-day and n-day vulnerabilities in enterprise software including GoAnywhere MFT, SmarterTools' SmarterMail, Microsoft Exchange, Ivanti Connect Secure, and JetBrains TeamCity, in some cases deploying an exploit a full week before the underlying vulnerability was ever publicly disclosed. Microsoft has separately observed the group move from initial network access to complete encryption in under 24 hours — a pace that leaves defenders very little room between detection and damage even when they are watching closely. StormEncryptor's appearance marks Microsoft's first observed Storm-1175 activity since that April campaign, and the company frames it explicitly as a shift away from Medusa rather than a continuation of it: this is the same operator that has spent the better part of a year proving it can move unusually fast, now apparently running its own strain rather than renting someone else's.

The strain itself is a fairly conventional piece of engineering — a C++ locker that appends the ".encrypted" extension to compromised files and drops a ransom note titled "!!!README_FIRST!!!.txt" into every directory it scans, giving victims three days to open negotiations before Storm-1175 threatens to leak the stolen data publicly. Once inside a network, the group's post-compromise toolkit reads like a familiar checklist rather than anything novel: AnyDesk or SimpleHelp for hands-on remote access, Advanced IP Scanner to map the internal network, and Mimikatz to dump credentials directly out of the LSASS process — tools chosen for reliability and speed rather than stealth, consistent with an operator whose entire competitive advantage is how fast it can move from foothold to encryption.

The genuinely alarming part of this story sits one layer beneath the malware, in how Storm-1175 is believed to be getting in. Microsoft has not formally confirmed the access vector, but StormEncryptor installations reportedly began the same day a critical flaw, CVE-2026-18577, was disclosed in N-central, a remote monitoring and management console used by managed service providers to administer client endpoints from a central location. N-able, the company behind N-central, has traced the vulnerability's first real-world exploitation to a zero-day attack on July 31 — several days before its own advisory went out — though it remains unclear whether Storm-1175 was behind that earliest activity or simply moved quickly once a usable technique was already circulating. Cybersecurity firm Huntress describes the flaw as granting unauthenticated, "god-mode" access — meaning an attacker needs no credentials at all to seize full administrative control of an N-central server, and by extension, every endpoint that server is trusted to manage. That structure turns a single successful intrusion into a multiplier: one compromised MSP doesn't yield one ransomware incident, it potentially yields one against every client that MSP serves, all from a single point of entry. This is not a theoretical concern specific to N-central, either — a nearly identical scenario played out in 2021, when a flaw in Kaseya's RMM software let the REvil ransomware group compromise 60 of Kaseya's direct customers and use that foothold to reach roughly 1,500 downstream organizations, and again in 2024, when a vulnerability in ConnectWise's ScreenConnect product fueled a wave of downstream ransomware campaigns — one that Microsoft says Storm-1175 itself participated in at the time. This is, in other words, an operator returning to a category of attack it has already run successfully once before, against a different RMM product, with a demonstrated appetite for turning one vulnerable vendor into many ransomed customers.

How many organizations are actually affected this time remains genuinely unresolved, and the uncertainty itself is worth sitting with rather than rounding up or down. N-able, the company behind N-central, says it has reached out to a limited number of impacted customers without specifying a count. Huntress has acknowledged that a small number of its own clients were affected and published a timeline showing how the attackers moved across downstream hosts in two documented cases, but stopped short of estimating the total number of downstream organizations touched by the campaign. That gap between a confirmed, serious vulnerability and an unconfirmed blast radius is precisely the position Kaseya customers found themselves in in the first days of 2021, before the true scale of that incident became clear — which is less a reassurance than a reason for any organization running a self-hosted N-central server to treat the exposure as urgent regardless of whether its own name has surfaced yet. N-able's own patching effort became part of this story rather than a clean resolution to it: its first hotfix, shipped August 2, turned out not to fully close the hole — attackers found a way around it — forcing N-able to issue a second emergency hotfix on August 6 with an explicit warning to customers that the initial fix had not been sufficient. Even that second round has not closed the exposure in practice: Huntress found that more than half of the reachable N-central cloud servers across its own partner base remained unpatched after fixes were available, alongside 28.6 percent of self-hosted instances. N-able has previously published specific indicators to check for, including an svchost.exe file appearing inside users' Documents folders, a registered service named Cloudflared that shouldn't be there, and inbound connections from IP addresses listed in its advisory — but Huntress's own recommendation for organizations in higher-risk environments where exposure can't be meaningfully reduced is blunter still: consider turning N-central off entirely, even while acknowledging that doing so means losing the central visibility, patching capability, and remote access an organization may need most in exactly this situation.

What makes Storm-1175 worth tracking as more than just another new ransomware name is the specific combination on display here: an operator with an already-proven record of exploiting vulnerabilities within days of disclosure and encrypting networks within hours of access, choosing to debut its independence from a known ransomware brand through exactly the kind of supply-chain vector that has twice before turned a single vendor compromise into a mass-casualty event for that vendor's entire customer base. The malware itself, a straightforward C++ locker with a standard toolkit behind it, is the least interesting part of this story. The interesting part is that a group with a documented history of speed and supply-chain opportunism has just shown, for the second time, that it knows exactly where the multiplier sits — and this time, whatever it does with a compromised network, it's doing entirely on its own terms.