Skip to content
feed: live
>_ 0dayNews
ransomware

Storm-1175 Drops Medusa, Deploys Custom StormEncryptor

Microsoft's threat intel team links China-backed Storm-1175 to StormEncryptor, a new C++ ransomware. MSPs on unpatched N-central are in the likely blast radius.

Storm-1175 Drops Medusa, Deploys Custom StormEncryptor
Image: AI-generated — no human photographer / 0dayNews AI Cover (comfyui) · Generated on-site infrastructure — no external license
fuse Marisol "Fuse" Delgado · Published · 2 min read

Microsoft’s Threat Intelligence team has attributed a new ransomware strain to Storm-1175, a China-linked financially motivated group that had been running Medusa ransomware operations. The new strain is called StormEncryptor. It’s written in C++ and renames encrypted files with the .encrypted extension.

Groups that transition from RaaS affiliate relationships to custom tooling tend not to go back. Track Storm-1175 as its own operation from here.

What Microsoft Found

According to Microsoft Threat Intelligence, Storm-1175 is a financially motivated group with China-state links. The group previously ran Medusa deployments; this deployment of StormEncryptor represents a documented shift to their own ransomware binary.

What’s confirmed: C++ binary, .encrypted extension on victim files, active deployment against real targets. Full technical indicators — encryption scheme, C2 infrastructure, ransom note format — are not yet public.

Early analysis suggests N-able’s N-central remote monitoring and management platform as a likely initial access vector. Microsoft has not officially confirmed this as of publication; treat it as unconfirmed but worth acting on now.

Priority Actions

If you’re an MSP or running N-central:

There is already a CISA KEV-listed authentication bypass in N-central. We covered it in detail when CISA added it earlier this month. If that patch isn’t applied yet, it goes to the top of the queue before anything else in this article.

Compromised RMM platforms mean Storm-1175 — or any operator with the same access — can move laterally to every managed endpoint downstream. Patch, then audit. In that order.

For everyone else:

  1. Search for .encrypted files. Check file servers, backup targets, and workstations. Unexpected hits mean you have an active incident, not a patching problem.
  2. Pull Microsoft’s Storm-1175 IOCs. Threat intelligence feeds should carry current indicators. Run them against your SIEM and EDR.
  3. Review RMM and remote-access logs. Look for anomalous session creation or lateral movement over the past two to three weeks.

Context

The shift from Medusa affiliate to custom tooling is operationally significant. RaaS affiliates split ransom payments with the operator — typically 20–30 percent goes to the ransomware developer. Running your own tool removes that split. As the cost of building functional ransomware has dropped, the financial calculus for capable groups has shifted toward going independent.

This week also brought a separate joint FBI/South Korea advisory on Gunra ransomware targeting critical infrastructure and government agencies. Different operation, overlapping target verticals. The common thread is that both campaigns route through known vulnerabilities in network perimeter gear and management platforms — exactly what’s on the CISA KEV list. That list exists for a reason.

Track active exploited vulnerabilities at our KEV tracker.

Found this useful? Share it.