< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-10T22:08:37+05:30

China-Linked Threat Actor Deploys StormEncryptor Ransomware via N-central Vulnerability

China-linked threat actor Storm-1175 deployed new StormEncryptor ransomware, exploiting the N-central vulnerability CVE-2026-18577. The ransomware appends .encrypted extensions to files and uses remote monitoring tools for post-compromise activities.

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.

The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.

"StormEncryptor is written in C++ and appends the file name extension .encrypted

Read original article

*** END OF TRANSMISSION ***