StormEncryptor is a custom C++ ransomware family associated with the financially motivated threat actor Storm-1175, which Microsoft assesses is likely China-based. The malware marks a shift from the actor’s earlier use of Medusa-associated ransomware deployments to a dedicated encryptor used in rapid, human-operated intrusion campaigns.
On compromised systems, StormEncryptor encrypts files, appends an additional encrypted-file extension, and drops ransom notes throughout affected directories. The ransom messaging supports double extortion by combining file encryption with threats to publish stolen data if payment demands are not met within a short deadline. Reported intrusions involving StormEncryptor have been characterized by high operational speed, with Storm-1175 moving from initial compromise to credential theft, remote administration, network discovery, data theft, and ransomware deployment within hours to a few days.
Observed StormEncryptor activity has been linked to campaigns that likely began through exploitation of newly disclosed vulnerabilities in exposed remote management infrastructure, particularly N-able N-central. Post-compromise operations attributed to the same actor included use of remote access tooling, credential dumping, and network enumeration to expand access before encryption. The broader actor tradecraft includes rapid exploitation of internet-facing systems, lateral movement, defense evasion, and exfiltration in support of ransomware operations.
Storm-1175 has targeted organizations in healthcare, education, finance, professional services, and related sectors, with victims reported in the United States, the United Kingdom, and Australia. Where remote monitoring and management platforms are involved, the operational risk is amplified because compromise of a management server can enable downstream impact across many managed endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the CISA Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026. | Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor.
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. "StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts," Microsoft noted.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Security researchers reported attackers exploiting the vulnerability to obtain highly privileged access and subsequently conduct reconnaissance and lateral movement across affected environments.
Look for AnyDesk, SimpleHelp, unexpected services, scheduled tasks, renamed tunneling tools, PowerShell abuse and antivirus exclusions.
Look for AnyDesk, SimpleHelp, unexpected services, scheduled tasks, renamed tunneling tools, PowerShell abuse and antivirus exclusions.
Look for AnyDesk, SimpleHelp, unexpected services, scheduled tasks, renamed tunneling tools, PowerShell abuse and antivirus exclusions.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware strain written in C++ that encrypts files, appends the .encrypted extension, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory.
An earlier undocumented ransomware strain installed by Storm-1175 in high-velocity campaigns, with Microsoft observing rapid progression from initial access to full encryption in less than 24 hours.
Ransomware variant written in C++ that encrypts files, appends the .encrypted extension, drops a ransom note named !!!README_FIRST!!!.txt in scanned directories, and threatens publication of stolen data if victims do not negotiate payment within three days.
A custom ransomware payload associated with Storm-1175. It encrypts files, appends the .encrypted extension, drops !!!README_FIRST!!!.txt ransom notes, and is used in double-extortion operations following rapid exploitation, lateral movement, credential theft, and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.