HomeIntelligenceBrief
BREACH BRIEF🟠 High Ransomware

Storm-1175 Deploys New StormEncryptor Ransomware via CVE‑2026‑18577 in N‑able Remote‑Management Software

China‑linked threat actor Storm‑1175 has begun using a new ransomware strain, StormEncryptor, that exploits the CVE‑2026‑18577 authentication‑bypass flaw in N‑able RMM. The rapid encryption of files underscores the need for continuous vulnerability‑management controls and SOC 2 evidence of patching.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 securityaffairs.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Storm-1175 Deploys New StormEncryptor Ransomware via CVE‑2026‑18577 in N‑able Remote‑Management Software

What Happened — China‑linked financially motivated group Storm‑1175 has switched from the Medusa ransomware family to a new C++‑based strain called StormEncryptor. The campaign appears to exploit the recently disclosed CVE‑2026‑18577 authentication‑bypass flaw in N‑able RMM, encrypting files, appending a “.encrypted” extension and dropping a ransom note in every scanned directory.

Why It Matters for Compliance & Audit Readiness

  • The attack illustrates a classic control gap: unpatched, internet‑facing systems that should be covered by a documented vulnerability‑management program.
  • SOC 2 auditors expect continuous evidence that patching, configuration monitoring, and change‑control processes are operating effectively; this incident provides a concrete example of why that evidence is critical.
  • Mapping the vulnerability‑remediation controls to the SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) criteria helps demonstrate due diligence and a defensible audit trail.

Who Is Affected — Healthcare, education, financial services, and professional services firms that run N‑able or similar remote‑management tools in the US, UK, and Australia.

Recommended Actions

  • Verify whether any N‑able endpoints are still running vulnerable versions; apply the vendor‑issued patch immediately.
  • Update your vulnerability‑management policy to include rapid triage of CVEs added to the CISA KEV list.
  • Capture patch‑deployment logs and configuration‑state snapshots as SOC 2 evidence of control execution.

Technical Notes

  • Attack vector: exploitation of CVE‑2026‑18577 (authentication bypass) → remote code execution → ransomware deployment.
  • Tools used: AnyDesk, SimpleHelp (remote access), Advanced IP Scanner (network mapping), Mimikatz (credential dumping).
  • Data impact: file encryption and potential data loss; no confirmed exfiltration reported.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/197119/malware/storm-1175-replaces-medusa-with-new-stormencryptor-ransomware.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →