Hackers Linked to China Could Be Exploiting Remote Software
A hooded man with a laptop sits in front of data in the shape of a Chinese flag. China has pursued state-sponsored hacking efforts as a tool of geopolitical influence against the United States. (Shutterstock/trambler58)
Hackers Linked to China Could Be Exploiting Remote Software
Share this link on Facebook
Share this page on X (Twitter)
Share this link on LinkedIn
Share this page on Reddit
Email a link to this page
The “Storm-1175” hacking group has developed a new type of malware, using multiple zero-day exploits to quickly take control of computer systems and hold them for ransom.
A hacking group that is believed to have links to China began to deploy a new ransomware strain earlier this month. According to Microsoft Threat Intelligence, the group known as “Storm-1175” reemerged after several months of inactivity, and moved away from its “Medusa” ransomware.
The newly released “StormEncryptor” ransomware is more worrisome, Microsoft researchers noted in a post on social media, stating it is written in C and that it can target remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and Windows Local Security Authority Subsystem Service. The tool exploits an authentication bypass vulnerability, which is tracked as CVE-2026-18577, in the networking monitoring provider N-able’s N-central platform.
“Storm-1175 is known to operate high-velocity ransomware campaigns that weaponize N-days, taking advantage of the window between vulnerability disclosure and patch adoption,” Microsoft Threat Intelligence warned.
N-able has already issued two emergency........
