New China-Linked Ransomware 'StormEncryptor' Signals Evolving Threat to Businesses
Microsoft has revealed that Storm-1175, a financially motivated hacking group with links to China, is now deploying a previously unknown type of ransomware called StormEncryptor. This marks a change in tactics for the group, which had previously used a different ransomware family known as Medusa.
According to Microsoft's Threat Intelligence Team, StormEncryptor is written in a programming language called C++ and encrypts victims' files, adding a distinctive '.encrypted' extension to affected files. The attack is believed to be linked to a vulnerability in N-central, a widely used IT management platform.
The emergence of new ransomware variants like StormEncryptor highlights how cybercriminal groups continue to develop and rotate their tools to evade detection and maximise impact. For small and medium businesses that rely on IT service providers or remote management software, this development is a reminder that vulnerabilities in third-party tools can create pathways for attackers, even if the business itself has strong internal security practices.