StormEncryptor Ransomware Targets N-central Environments
Microsoft described Storm-1175 in April as a financially motivated actor that rapidly weaponizes vulnerabilities in internet-facing systems. Its earlier Medusa operations affected healthcare, education, professional services and finance organizations in Australia, the United Kingdom and the United States, with some intrusions progressing from initial access to ransomware deployment within 24 hours.
According to the latest reporting, Microsoft assesses that exploitation of N-central may provide initial access in the StormEncryptor activity, but the precise entry point has not been conclusively established. The assessment follows active exploitation of CVE-2026-18577, an authentication bypass that remained after an earlier N-central fix. N-able released additional mitigation in N-central 2026.3 hotfix 2 on August 6 and urged customers to update.
BleepingComputer reported that StormEncryptor is written in C++ and adds the .encrypted extension to files. The malware also places a ransom note named !!!README_FIRST!!!.txt in directories it processes. Microsoft has previously observed Storm-1175 stealing credentials, creating administrator accounts, deploying remote management tools, tampering with security products, collecting files and exfiltrating data before encryption.
N-central is designed to administer many downstream endpoints, so compromise of a management server can extend an attack across customer environments. Huntress reported exploitation across multiple organizations and advised operators with internet-reachable, unpatched servers to consider taking N-central offline until protected. N-able said hosted systems received mitigations, while on-premises customers must apply the available hotfixes and review their environments for unauthorized access.
Defenders should install the latest N-central hotfix, restrict management interfaces to trusted networks and audit newly created accounts, scripts, remote sessions and agent deployments. They should also investigate unexpected remote-access software, credential-dumping activity, security-control changes and sudden creation of files bearing the .encrypted extension. Because patching does not remove an existing foothold, incident review and credential rotation remain necessary where compromise is suspected.