Rt By @hiphoponelove_: On August 2, 2026, The Financially Motivated Cybercriminal Actor Tracked By Microsoft Threat Intelligence As Storm-1175 Began Deploying A New Ransomware Strain Called Stormencryptor. Storm-1175’s Deployment Of Stormencryptor Marks The Threat Actor’s First Activity Observed By
On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use.
StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory.
While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.
Storm-1175 is known to operate high-velocity ransomware campaigns that weaponize N-days, taking advantage of the window between vulnerability disclosure and patch adoption. msft.it/6010a1njK
In this new activity, Storm-1175’s post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz.
This threat actor is known to rapidly move from initial access to data exfiltration and ransomware deployment, often within a few days. Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.
Microsoft Defender Antivirus detects StormEncryptor (SHA-256: c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054) as Ransom:Win64/StormEncryptor. Microsoft Defender for Endpoint detects this activity through multiple alerts, including “Hands-on-keyboard attack involving multiple devices” and “Potential human-operated malicious activity”.
Popular Products
-
Smart GPS Waterproof Mini Pet Tracker$59.56$29.78 -
Unisex Adjustable Back Posture Corrector$71.56$35.78 -
Smart Bluetooth Aroma Diffuser$585.56$292.87 -
Enamel Heart Pendant Necklace$49.56$24.78 -
Digital Electronic Smart Door Lock wi...$211.78$105.89