China-Linked Group Deploys New StormEncryptor Ransomware
Microsoft identifies Storm-1175 using a new C++-based ransomware strain. The group has shifted from Medusa to StormEncryptor, targeting enterprise systems.
TL;DR
- Storm-1175, a China-linked financially motivated hacker group, is now using StormEncryptor ransomware.
- StormEncryptor is written in C++ and appends the .encrypted file extension.
- This marks a departure from their prior use of Medusa ransomware.
- Attack vector likely involves exploitation of an N-central vulnerability.
- Organizations should review Microsoft’s threat report and patch N-central systems immediately.
Microsoft’s Threat Intelligence Team has uncovered a notable evolution in tactics by Storm-1175, a financially driven cyber threat actor with ties to China. This group has moved away from its previous Medusa ransomware and is now leveraging a newly identified strain known as StormEncryptor.
Written in C++, StormEncryptor appends the .encrypted extension to compromised files, signaling a technical shift in the group’s operations. Initial analysis suggests the attackers may be exploiting a flaw in N-central systems to gain initial access, highlighting the importance of timely patching and monitoring for enterprise environments.
About StormEncryptor
- StormEncryptor is a newly documented ransomware written in C++.
- It appends the .encrypted file extension to affected files during encryption.
- The malware represents a strategic shift from the group’s prior use of Medusa ransomware.
- Its deployment indicates increased sophistication and potential reuse of existing toolsets.
Attack Vector and Mitigation
- Initial compromise is suspected to occur through exploitation of an N-central vulnerability.
- Organizations using N-central platforms should apply available patches immediately.
- Microsoft recommends network segmentation and monitoring for unusual file encryption behavior.
- Reviewing indicators of compromise (IOCs) provided by Microsoft can help detect ongoing intrusions.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.