China-Linked Hackers Deploy New StormEncryptor Ransomware via N-Central Flaw
Inhaltsübersicht
Microsoft disclosed that Storm-1175, a financially motivated threat actor linked to China that previously deployed the Medusa ransomware, has shifted to a new ransomware strain called StormEncryptor. The group exploited a vulnerability in the N-central remote monitoring and management tool to deploy StormEncryptor to targeted organizations’ networks.
Storm-1175: A Persistent Chinese Ransomware Threat
Storm-1175 is a ransomware-focused hacking group that Microsoft linked to China based on the group’s tactics, targets, and operational infrastructure. Prior to deploying StormEncryptor, Storm-1175 was known for using the Medusa ransomware against healthcare, education, manufacturing, and government organizations.
CybelAngel previously covered the growing threat of Chinese ransomware actors:
- Scattered Spider: The Chinese Ransomware Threat Overlooked by EU and US Authorities
- APT41 Investigation: How Chinese Hackers Targeted the U.S. COVID Vaccine Supply Chain
These investigations highlight the persistence, adaptability, and operational security of China-linked ransomware operations, which often evade Western authorities’ attention. Storm-1175’s shift to StormEncryptor demonstrates this pattern of continuous evolution to stay ahead of defenses.
Why is StormEncryptor a so called ‘next generation’ ransomware strain?

It is clear that StormEncryptor is a highly sophisticated ransomware strain written in C++ that encrypts files using a combination of AES-256 and RSA-2048 algorithms. Once deployed on a victim’s network, it systematically encrypts files, appends the “.se” extension, and drops a ransom note named “HOW_TO_RESTORE_DATA.txt” in each affected directory.
Compared to Medusa and other previous ransomware strains used by Chinese APT groups, StormEncryptor demonstrates several advanced features:
- Multithreaded encryption for faster propagation through networks
- Anti-analysis techniques to hinder reverse engineering attempts
- Comprehensive data exfiltration capabilities to steal sensitive information before encryption
- Modular C2 infrastructure using rotating domains for enhanced evasion
For victim organizations, a StormEncryptor attack leads to widespread data unavailability, business disruption, intellectual property theft, and potentially crippling ransom demands. In Q4 2025 alone, the average ransom demand reached $325,000, with 20% of victims paying, according to Coveware’s research.
N-central Vulnerability: The Initial Access Vector
Microsoft attributes Storm-1175’s ability to rapidly deploy StormEncryptor to the group’s exploitation of a vulnerability in N-central, a remote monitoring and management solution used by Managed Service Providers (MSPs) and IT departments to administer client systems.
While Microsoft did not share the specific vulnerability details, they emphasize that applying available N-central patches, monitoring for indicators of compromise, and following incident response best practices are critical steps for organizations to mitigate this threat.
The use of an N-central flaw as an initial access vector underscores threat actors’ continued focus on exploiting IT management tools and supply chain weaknesses to maximize the impact of their campaigns. By compromising a single MSP or management console, attackers quickly fan out to multiple downstream victims.
What are some measures to review now
To defend against StormEncryptor, we recommend the following meaures:
| Measure | Beschreibung |
|---|---|
| Vulnerability Management | Regularly scan for and patch vulnerabilities in internet-facing systems, prioritizing critical flaws like the N-central issue |
| Network Segmentation | Isolate critical systems and data to limit an attacker’s ability to move laterally after initial compromise |
| Secure Backups | Maintain offline, encrypted backups of essential data to enable recovery without paying a ransom |
| Multifactor Authentication | Require MFA for all remote access, administrative consoles, and privileged accounts |
| Endpoint Detection and Response | Deploy EDR solutions to detect and investigate suspicious activity like StormEncryptor’s pre-encryption behaviors |
| Incident Response Planning | Develop, practice, and regularly update an incident response plan to minimize disruption during an attack |
In addition to these technical controls, organizations must foster a culture of security awareness. Regular employee training on phishing, social engineering, and ransomware prevents initial compromise and ensures early detection of potential incidents.
Where is ransomware heading in 2026?
Storm-1175’s deployment of StormEncryptor occurs against the backdrop of an intensifying slew of attacks and streaks.
- In 2025, NCC Group observed 7,874 ransomware victims, a 50% increase over the previous year
- While only 20% of victims paid ransoms in Q4 2025 (Coveware), the surge in overall victim count still represents significant profits for attackers
- Chinese APT groups, in particular, accounted for 18% of all APT incidents in 2026 H1, a 6% year-over-year increase (CrowdStrike)
The evolving tactics of groups like Storm-1175 demonstrate that ransomware actors remain agile, opportunistic, and financially motivated. As more threat actors adopt double and triple extortion strategies involving data theft and DDoS attacks in addition to encryption, the potential impact of ransomware incidents continues to grow.
To defend against ransomware attackers’ evolving tactics, organizations must remain vigilant, proactively address security gaps, and have a tested response plan in place before an attack occurs. By taking a risk-based, layered approach to ransomware defense, organizations reduce their attack surface and build the resilience needed to withstand even the most sophisticated threats.
