StormEncryptor Ransomware (Storm-1175)
First seen Aug 11, 2026 · Updated Aug 11, 2026
Microsoft has identified Storm-1175, a financially motivated China-linked threat actor, deploying a new ransomware strain called StormEncryptor, marking a shift from their prior use of Medusa ransomware. Initial access is suspected to involve exploitation of a flaw in N-central, a remote monitoring and management (RMM) platform commonly used by MSPs to administer client endpoints and infrastructure.
Technical Analysis
StormEncryptor is written in C++ and encrypts victim files, appending the .encrypted extension, indicating a custom-built payload rather than a ransomware-as-a-service leverage. The suspected initial access vector is a vulnerability in N-central, an RMM tool widely used by managed service providers, which if confirmed would allow lateral movement and mass deployment across multiple downstream client environments. This pivot from Medusa suggests Storm-1175 is investing in proprietary tooling, potentially to evade detection signatures tied to known ransomware families. Organizations running AI agent orchestration or automation on infrastructure managed via N-central or similar RMM platforms face risk of credential theft, agent runtime compromise, or encryption of model artifacts and pipeline data if the RMM tool is exploited as an entry point.
Affected Systems
N-central RMM platform (specific vulnerable version not yet disclosed), Windows endpoints managed via compromised RMM instances, MSP client environments
Indicators of Compromise
- File extension: .encrypted
- Ransomware name: StormEncryptor.exe (reported name, hash not disclosed)
- Threat actor designation: Storm-1175
- Prior toolset: Medusa ransomware
Remediation Steps
- 1
Patch and audit N-central deployments
Verify current N-central version against vendor advisories, apply available patches, and review access logs for anomalous administrative activity.
- 2
Restrict RMM tool exposure
Limit external/internet-facing access to RMM consoles, enforce MFA, and apply least-privilege access controls for MSP technicians.
- 3
Deploy endpoint detection for StormEncryptor behavior
Update EDR/AV signatures to detect C++-based ransomware payloads and monitor for mass file renaming to .encrypted extension.
- 4
Segment and back up critical systems
Maintain offline, immutable backups of critical data and segment networks to limit lateral movement from compromised RMM access.
- 5
Review agent and automation credentials
For organizations running AI agents or automation tied to RMM-managed hosts, rotate API keys and credentials, and audit agent access scopes to limit blast radius from a host compromise.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.