Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > China-Linked Hackers Switch to Custom StormEncryptor Ransomware

China-Linked Hackers Switch to Custom StormEncryptor Ransomware

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 11, 2026

Human Written
China-Linked Hackers Switch to Custom StormEncryptor Ransomware
  • Storm-1175, a China-linked cybercrime group, has changed from Medusa ransomware to a custom C++ locker called StormEncryptor that appends the .encrypted extension.

  • Attackers likely used CVE-2026-18577 in N-able N-central to bypass authentication and gain full administrative control over management servers.

  • The group uses tools like Mimikatz, AnyDesk, and Advanced IP Scanner, these aid it to dump LSASS memory, steal credentials, and encrypt systems within days.

Microsoft intelligence experts have recently detected a new ransomware operation with ties to a cybercriminal organization based in China. The hackers, referred to as Storm-1175, have released a new file encryption program, StormEncryptor, across target networks.

Investigators noticed the campaign right after attackers exploited a fresh software vulnerability inside widely used remote management platforms.

This sudden shift highlights how fast financially motivated hackers change their digital attack tools to stay ahead of defenders. Storm-1175 previously relied on the well-known Medusa ransomware to lock victim machines during extortion attempts.

Switching to a custom-built file locker gives the group new ways to breach enterprise systems while avoiding standard security detection tools. 

Exploiting Vulnerabilities in Remote Management Tools to Gain System Entry

The malicious players probably entered the systems of the victims by abusing a bug in N-able N-central.  This was the bug with reference number CVE-2026-18577 that allowed remote cybercriminals to bypass basic authentication requirements and to take over administrative accounts. Experts made a conclusion that this bug acts as a workaround for the old bug CVE-2026-18556.

However, many organization administrators failed to apply emergency software fixes before hackers began scanning the internet for exposed servers. Unauthenticated attackers can use this secondary entry path to gain complete administrative power over central management consoles. Because managed service providers use N-central to control remote client computers, compromising one server grants access to many business networks.

The United States Cybersecurity and Infrastructure Security Agency swiftly put both defects on its list of known vulnerabilities. Security experts warned corporate network administrators that there is active exploitation of these vulnerabilities across various sectors of the economy. Consequently, unpatched servers leave downstream client machines completely exposed to sudden remote network takeovers. 

Attackers move quickly once they gain initial administrative access through the management portal. They register background communication channels to preserve access across system reboots, this stealthy strategy allows attackers to maintain control over compromised machines without triggering standard firewall alarms.

Technical Analysis of StormEncryptor and Post-Compromise Tools

After gaining access, the hackers deploy the new C++ binary file to begin file-locking routines. The program appends the .encrypted extension to every locked document, spreadsheet, and database it finds on local drives. It also drops a text file titled ‘README_FIRST’ into scanned folders to give victims ransom instructions.

Furthermore, attackers use different valid administrative programs to move through compromised corporate networks. They apply remote administration applications like AnyDesk and SimpleHelp to gain stable access to internal systems. The group also runs Advanced IP Scanner to map out surrounding network devices and find high-value targets.

To steal elevated network credentials, the group performs LSASS dumping by executing the Mimikatz software utility. Taking domain credentials from system memory allows the attackers to escalate privileges across entire corporate environments. In addition, stealing domain administrator credentials lets the hackers spread their file-locking software to every connected server quickly.

According to threat reports from Microsoft, the group completes these steps within a very short timeframe. The attackers often move from initial entry to mass file encryption in just a few days. That rapid pace leaves network defense teams very little time to stop active intrusions manually.

The speed of these attacks is reminiscent of a growing trend in autonomous cyber threats. The JadePuffer AI agent was observed executing a ransomware attack on AI infrastructure, iteratively developing six Python scripts in just over five minutes to overcome technical obstacles and deploy custom EncForge ransomware.

Historical Exploits and Protective Actions for Network Defenders

Storm-1175 has a significant past in using software vulnerabilities for attacking global networks with file-locking payloads. It has previously used Mirth Connect vulnerabilities for hacking healthcare information technology systems. Recently, the group also utilized CVE-2024-1709 and CVE-2024-1708 vulnerabilities to compromise ConnectWise ScreenConnect and deliver Medusa ransomware.

Furthermore, the hackers utilized bugs in JetBrains TeamCity to breach software build pipelines – and they also leveraged CVE-2023-48788 to attack Fortinet FortiClient EMS to enter corporate networks. Late last year analysts uncovered that hackers took advantage of a flaw and attacked Fortra GoAnywhere to obtain access to file transfer solutions.

These moves show that these hackers use the small gap that exists between the public disclosure of bugs and vendor patch installations. They seem to be using both zero-day exploits and unpatched bugs to get into internet-based apps before the IT teams complete the process of updating the software. This means that organizations need to act quickly to select the needed patches and prevent any hacking activity from hackers on exposed management portals. 

Systems administrators must regularly scrutinize user profiles as well as limit remote access to the console through reliable networks. The implementation of multi-factor verification would go a long way towards preventing unauthorized takeover of accounts. Companies must also separate the backups from the rest of the infrastructure to ensure quick recovery from a possible ransomware attack on the servers.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.