← Back to blog

China-Linked Group Deploys New StormEncryptor Ransomware

Microsoft identifies Storm-1175 using a new C++-based ransomware strain. The group has shifted from Medusa to StormEncryptor, targeting enterprise systems.

TL;DR

  • Storm-1175, a China-linked financially motivated hacker group, is now using StormEncryptor ransomware.
  • StormEncryptor is written in C++ and appends the .encrypted file extension.
  • This marks a departure from their prior use of Medusa ransomware.
  • Attack vector likely involves exploitation of an N-central vulnerability.
  • Organizations should review Microsoft’s threat report and patch N-central systems immediately.

Microsoft’s Threat Intelligence Team has uncovered a notable evolution in tactics by Storm-1175, a financially driven cyber threat actor with ties to China. This group has moved away from its previous Medusa ransomware and is now leveraging a newly identified strain known as StormEncryptor.

Written in C++, StormEncryptor appends the .encrypted extension to compromised files, signaling a technical shift in the group’s operations. Initial analysis suggests the attackers may be exploiting a flaw in N-central systems to gain initial access, highlighting the importance of timely patching and monitoring for enterprise environments.

About StormEncryptor

  • StormEncryptor is a newly documented ransomware written in C++.
  • It appends the .encrypted file extension to affected files during encryption.
  • The malware represents a strategic shift from the group’s prior use of Medusa ransomware.
  • Its deployment indicates increased sophistication and potential reuse of existing toolsets.

Attack Vector and Mitigation

  • Initial compromise is suspected to occur through exploitation of an N-central vulnerability.
  • Organizations using N-central platforms should apply available patches immediately.
  • Microsoft recommends network segmentation and monitoring for unusual file encryption behavior.
  • Reviewing indicators of compromise (IOCs) provided by Microsoft can help detect ongoing intrusions.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

China-Linked Group Deploys New StormEncryptor Ransomware — Agent Breach Blog | Agent Breach