New StormEncryptor ransomware used by former Medusa affiliate
Aug 10, 2026, 05:42 PM · by BleepingComputer
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. Ransomware operators in this campaign appear to follow the double-extortion playbook, threatening to publish stolen data if the ransom demand is not met. Security teams should review their detection rules, keep threat-intelligence feeds current, and validate that incident-response runbooks are tested before an incident occurs.
Source: BleepingComputer