Microsoft Threat Intelligence has identified a financially driven threat actor, known as Storm-1175, deploying a previously unreported ransomware family called StormEncryptor starting August 2nd, 2026 This article explores stormencryptor ransomware microsoft. . This activity marks the group's first public campaign since April and signals a shift from Medusa ransomware, which they previously used in extortion tactics.

Storm-1175 Utilizes New StormEncryptor Ransomware While Microsoft has not confirmed the initial access vector, the timing strongly suggests that Storm-1175 is leveraging this newly disclosed flaw to compromise exposed environments before organizations can complete patching. Microsoft Defender Antivirus identifies the StormEncryptor sample as Ransom:Win64/StormEncryptor.

Endpoint Protection can also detect associated keyboard activities through alerts, including "Hands-on-keyboard attack involving multiple devices" and "Potential human-operated malicious activity." The malware was first disclosed on August 2nd and added to CISA's Known Exploited Vulnerabilities catalog on the same day, highlighting evidence of active exploitation. Organizations that delay patching of internet-facing remote management infrastructure can inadvertently grant attackers privileged access, opportunities for persistence, and a means to infiltrate connected customer or enterprise systems.

Credential-access activities include dumping the Local Security Authority Subsystem Service process with Mimikatz, enabling attackers to obtain credentials and potentially expand across a victim’s network. Mitigation Organizations using Nable products should prioritize applying vendor security updates addressing CVE-2026-18577 and verify that internet-facing management interfaces are necessary, restricted, and strongly authenticated.