China-Linked Hackers Unleash New StormEncryptor Ransomware via N-Central Flaw
A financially motivated threat actor linked to China has been deploying a new ransomware strain called StormEncryptor, according to Microsoft. This marks a shift from the adversary's previous use of Medusa ransomware.
The tech giant said that the exact vulnerability exploited by the threat actor is unclear but likely involves the exploitation of CVE-2026-18577, a newly disclosed security flaw in N-able N-central, to obtain initial access. This vulnerability allows authentication bypass and account takeover in susceptible versions.
StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory.