> China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
[DATE: 10/08/2026 16:38]
[LANGUAGE: EN]
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.
The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.
"StormEncryptor is written in C++ and appends the file name extension .encrypted