Actor Profile
Storm-1175 is a China-linked, financially motivated threat actor tracked by Microsoft. The group specializes in high-velocity ransomware operations, exploiting both zero-day and N-day vulnerabilities in internet-facing enterprise software to gain initial access. Storm-1175 weaponizes the window between vulnerability disclosure and patch adoption, rapidly moving from compromise to data exfiltration and ransomware deployment—often within days. The actor has shifted from deploying Medusa ransomware to a new custom strain called StormEncryptor, written in C++.
TTPs (Tactics, Techniques, Procedures)
Storm-1175 exploits vulnerabilities in enterprise software for initial access, including CVE-2026-18577 (N-able N-central authentication bypass), CVE-2023-37679/CVE-2023-43208 (Mirth Connect), CVE-2024-1709/CVE-2024-1708 (ConnectWise ScreenConnect), CVE-2024-27198/CVE-2024-27199 (JetBrains TeamCity), CVE-2023-48788 (Fortinet FortiClient EMS), and CVE-2025-10035 (Fortra GoAnywhere). Post-compromise TTPs include abuse of remote monitoring and management tools (AnyDesk, SimpleHelp), network discovery via Advanced IP Scanner, credential dumping using Mimikatz (LSASS), data exfiltration, and ransomware deployment. StormEncryptor appends .encrypted extensions and drops ransom notes named !!!README_FIRST!!!.txt in every directory.
Targets & Patterns
Storm-1175 targets organizations with vulnerable internet-facing enterprise management and remote access software. The actor focuses on systems running N-able N-central, Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, Fortinet FortiClient EMS, and Fortra GoAnywhere. The targeting pattern suggests opportunistic exploitation of high-value enterprise environments where patch deployment lags behind disclosure. The financially motivated nature indicates targets are selected based on ransomware payment potential rather than geopolitical objectives, despite the China nexus. The rapid attack tempo (initial access to ransomware deployment within days) suggests targeting of organizations with weak detection and response capabilities.
Historical Context
Storm-1175 has historically deployed Medusa ransomware following exploitation of enterprise software vulnerabilities. Microsoft attributed the group to Medusa campaigns exploiting Mirth Connect (2023), Fortinet FortiClient EMS (2023), ConnectWise ScreenConnect (2024), JetBrains TeamCity (2024), and Fortra GoAnywhere (October 2025). The August 2026 disclosure marks a tactical shift to StormEncryptor, a custom C++-based ransomware, while maintaining the same exploitation-focused initial access methodology. CVE-2026-18577 and CVE-2026-18556 (N-able N-central) have been flagged by CISA as actively exploited, consistent with Storm-1175's pattern of weaponizing newly disclosed vulnerabilities.
Defensive Recommendations
- Immediately patch CVE-2026-18577 and CVE-2026-18556 in N-able N-central; prioritize patching all internet-facing enterprise management platforms including Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, Fortinet FortiClient EMS, and Fortra GoAnywhere
- Monitor for unauthorized deployment of remote monitoring tools (AnyDesk, SimpleHelp) and network scanning activity from Advanced IP Scanner; baseline legitimate RMM usage and alert on anomalies
- Detect LSASS credential dumping via Mimikatz by monitoring for process access to lsass.exe (Sysmon Event ID 10) and suspicious use of debugging privileges (SeDebugPrivilege)
- Implement behavioral detection for rapid lateral movement and data staging activity within 24-72 hours of initial access; Storm-1175 operates at high velocity from compromise to ransomware deployment
- Hunt for StormEncryptor indicators: .encrypted file extensions, ransom notes named !!!README_FIRST!!!.txt, and C++ compiled executables with file encryption behavior; establish file integrity monitoring on critical directories
---
# Geopolitical Context
Geopolitical Context
The disclosure of Storm-1175's deployment of StormEncryptor ransomware reflects an evolving pattern in which financially motivated threat actors linked to China exploit vulnerabilities in enterprise software for rapid monetization. Microsoft's attribution of Storm-1175 to China positions this activity within a broader context of cyber operations originating from or linked to Chinese territory, though the actor's financial motivation distinguishes it from state-sponsored espionage campaigns typically associated with Chinese advanced persistent threat (APT) groups. The actor's demonstrated capability to weaponize both zero-day and N-day vulnerabilities—including recent exploitation of CVE-2026-18577 in N-able N-central—suggests access to vulnerability research resources and a sophisticated understanding of enterprise attack surfaces. The group's high-velocity operational tempo, moving from initial access to ransomware deployment within days, indicates a mature operational model optimized for financial gain rather than strategic intelligence collection.
State Actor Alignment
Storm-1175 is characterized by Microsoft as a financially motivated threat actor linked to China, rather than a state-sponsored entity. This distinction is significant: while the group operates from or maintains connections to Chinese territory, its ransomware operations appear driven by profit rather than strategic state objectives. The actor's targeting pattern—exploiting vulnerabilities in widely deployed enterprise software from vendors including N-able, ConnectWise, JetBrains, Fortinet, and Fortra—is consistent with opportunistic cybercrime rather than targeted espionage. However, the group's technical sophistication and rapid exploitation capabilities raise questions about potential overlap with or tolerance by Chinese authorities. To date, no public sanctions or formal attribution statements from Western governments specifically targeting Storm-1175 have been disclosed, though the U.S. CISA's flagging of exploited vulnerabilities indicates heightened concern about the threat landscape this actor contributes to.
Business Impacty pro region
Storm-1175's operations have global implications given the widespread deployment of targeted enterprise software across North America, Europe, and Asia-Pacific. The exploitation of N-able N-central, ConnectWise ScreenConnect, and similar remote management platforms poses particular risk to managed service providers (MSPs) and their downstream clients, potentially enabling supply chain compromise scenarios. European organizations relying on affected software face exposure during the critical window between vulnerability disclosure and patch deployment—a period Storm-1175 has demonstrated ability to exploit effectively. The actor's use of tools like AnyDesk and SimpleHelp for post-compromise activity also highlights risks associated with legitimate remote administration software in enterprise environments. For European cybersecurity authorities and CERT teams, this activity underscores the need for accelerated patch management processes and enhanced monitoring of internet-facing enterprise applications, particularly in sectors dependent on remote management infrastructure.
Forecast
If Storm-1175 continues its established operational pattern, further ransomware campaigns exploiting newly disclosed vulnerabilities in enterprise software are likely in the near term. The shift from Medusa to StormEncryptor may indicate efforts to evade detection or differentiate the group's operations from other ransomware actors, though the core tactics—rapid exploitation, credential theft via Mimikatz, and swift data exfiltration—appear consistent. Should the group maintain access to zero-day or early N-day vulnerabilities, organizations with slower patch cycles will remain at elevated risk. If Western governments determine that Storm-1175's operations warrant formal attribution or sanctions—particularly if evidence emerges of state tolerance or support—this could trigger diplomatic responses or coordinated law enforcement action. In the absence of such measures, financially motivated actors linked to China may continue to operate with relative impunity, exploiting the gap between vulnerability disclosure and widespread patch adoption across global enterprise networks.
