3w ago · hacker-news
Storm-1175, a China-linked financially motivated threat actor, has deployed a new ransomware named StormEncryptor, written in C++, which appends the '.encrypted' extension to encrypted files and drops a ransom note titled '!!!README_FIRST!!!.txt'. The group likely gained initial access by exploiting CVE-2026-18577, a patch bypass vulnerability in N-able N-central, which allows authentication bypass and account takeover. Storm-1175 has a history of exploiting vulnerabilities in internet-facing systems, rapidly moving from initial access to data exfiltration and ransomware deployment within days, using tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for credential dumping.