AI Weekly Malaysia

Back to items Summaries

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

ID
12848
Status
summarized
Published
11 Aug 2026, 12:38 AM
Fetched
11 Aug 2026, 3:45 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.5
Created
11 Aug 2026, 3:49 AM
Tags
Audience
developerssaas_founders

What happened

Microsoft reports that China-linked threat actor Storm-1175 has switched from Medusa ransomware to a new C++ strain called StormEncryptor, which appends .encrypted to files and drops a !!!README_FIRST!!!.txt ransom note. Initial access likely exploits CVE-2026-18577, a patch bypass for CVE-2026-18556 in N-able N-central, both allowing authentication bypass and account takeover; CISA has flagged them as actively exploited. Post-compromise behavior includes AnyDesk or SimpleHelp abuse, Advanced IP Scanner for discovery, and Mimikatz for LSASS dumping.

Why it matters

If your team or MSP runs N-able N-central, patch immediately for CVE-2026-18577 and CVE-2026-18556 and audit for AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz activity as compromise indicators. For everyone else not running N-central, no action is required from this specific report.

Discussion angle

The narrow relevance here is whether any audience member relies on N-able N-central or an MSP that does; otherwise this is a reminder that RMM tools remain a favored initial-access vector and patch latency is the real attack surface.

Top