A China-linked threat actor, known as Storm-1175, has been identified as the operator of a new ransomware variant called StormEncryptor. This malware, written in C++, appends the .encrypted extension to compromised files. Notably, StormEncryptor represents a departure from the group's previous reliance on Medusa ransomware. The emergence of StormEncryptor may be linked to the exploitation of a vulnerability in N-central, although the exact attack vector is not confirmed. Microsoft's Threat Intelligence Team has disclosed the existence of StormEncryptor, highlighting the evolving tactics of Storm-11751. The use of this new ransomware strain underscores the importance of robust operational resilience planning, particularly in sectors that are frequently targeted by ransomware attacks. So what matters most to practitioners is that this development signals a potential increase in ransomware attacks leveraging newly discovered vulnerabilities, making it essential to prioritize proactive defense strategies.
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
⚡ High Priority
Why This Matters
Ransomware targeting Microsoft highlights sector-specific risk — operational resilience planning is the real takeaway.
References
- The Hacker News. (2026, August 10). China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw. *The Hacker News*. https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
Original Source
The Hacker News
Read original →