New StormEncryptor ransomware used by former Medusa affiliate

A New Storm Rages on: Former Medusa Affiliate Deploys StormEncryptor Ransomware

A financially motivated threat actor previously linked to the notorious Medusa ransomware operation has resurfaced with a new strain of malware called StormEncryptor. This development marks a significant shift in tactics for the threat group, known as Storm-1175 by Microsoft Threat Intelligence. According to researchers, this China-based actor has been exploiting vulnerabilities in various products to gain access to targeted systems and deploy the new ransomware.

StormEncryptor is a C++ malware that encrypts files on infected systems, appending the “.encrypted” filename extension and leaving behind a ransom note with a ominous message. The note gives victims three days to negotiate a ransom payment or face the threat of stolen data being leaked online. This aggressive approach highlights the growing sophistication of modern ransomware attacks, which often combine stealthy initial access techniques with rapid data exfiltration and encryption.

The researchers found that Storm-1175 uses various tools to gain control over targeted networks, including remote management software like AnyDesk or SimpleHelp, network discovery tools like Advanced IP Scanner, and credential dumping tools like Mimikatz. This multi-tool approach allows the threat actor to move quickly from initial compromise to data exfiltration and ransomware deployment, often within a matter of days.

Microsoft warns that Storm-1175 is known for its rapid pace, urging system administrators managing self-hosted N-central servers to take immediate action to secure their systems. The researchers recommend monitoring for Storm-1175 activity and applying security patches as soon as possible. In this case, the vulnerability exploited by the threat actor was addressed via a hotfix released on August 2, which should be installed immediately.

The emergence of StormEncryptor highlights the ongoing cat-and-mouse game between threat actors and security researchers. As new vulnerabilities are discovered and patched, threat groups adapt and evolve their tactics to stay ahead of the curve. To mitigate this risk, organizations must prioritize regular security patching, monitor for suspicious activity, and implement robust detection mechanisms.

In practical terms, system administrators should take a proactive approach to securing their networks by regularly scanning for vulnerabilities, applying patches in a timely manner, and monitoring for signs of compromise. By staying vigilant and adapting to emerging threats, organizations can reduce the risk of falling victim to attacks like StormEncryptor.


Source: Bleeping Computer — 2026-08-10