Threat Intelligence

New China-Linked Ransomware 'StormEncryptor' Signals Evolving Threat to Businesses

The Hacker News · 11 Aug 2026
Key Takeaway If your business uses IT management or remote support software, ensure it is kept fully patched and ask your provider about recent security updates.

Microsoft has revealed that Storm-1175, a financially motivated hacking group with links to China, is now deploying a previously unknown type of ransomware called StormEncryptor. This marks a change in tactics for the group, which had previously used a different ransomware family known as Medusa.

According to Microsoft's Threat Intelligence Team, StormEncryptor is written in a programming language called C++ and encrypts victims' files, adding a distinctive '.encrypted' extension to affected files. The attack is believed to be linked to a vulnerability in N-central, a widely used IT management platform.

The emergence of new ransomware variants like StormEncryptor highlights how cybercriminal groups continue to develop and rotate their tools to evade detection and maximise impact. For small and medium businesses that rely on IT service providers or remote management software, this development is a reminder that vulnerabilities in third-party tools can create pathways for attackers, even if the business itself has strong internal security practices.

ransomware China-linked threat actor vulnerability management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.