China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
- ID
- 12848
- Status
- summarized
- Published
- 11 Aug 2026, 12:38 AM
- Fetched
- 11 Aug 2026, 3:45 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.5
- Created
- 11 Aug 2026, 3:49 AM
- Tags
- Audience
- developerssaas_founders
What happened
Microsoft reports that China-linked threat actor Storm-1175 has switched from Medusa ransomware to a new C++ strain called StormEncryptor, which appends .encrypted to files and drops a !!!README_FIRST!!!.txt ransom note. Initial access likely exploits CVE-2026-18577, a patch bypass for CVE-2026-18556 in N-able N-central, both allowing authentication bypass and account takeover; CISA has flagged them as actively exploited. Post-compromise behavior includes AnyDesk or SimpleHelp abuse, Advanced IP Scanner for discovery, and Mimikatz for LSASS dumping.
Why it matters
If your team or MSP runs N-able N-central, patch immediately for CVE-2026-18577 and CVE-2026-18556 and audit for AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz activity as compromise indicators. For everyone else not running N-central, no action is required from this specific report.
Discussion angle
The narrow relevance here is whether any audience member relies on N-able N-central or an MSP that does; otherwise this is a reminder that RMM tools remain a favored initial-access vector and patch latency is the real attack surface.