CyberNews
← Back to dashboard
NEWS The Hacker News Ransomware

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Aug 10, 2026, 04:38 PM · by The Hacker News

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

For defenders, the ransomware lifecycle — initial access, lateral movement, exfiltration, and encryption — offers multiple points where early intervention can prevent a full-scale incident.

Security teams should review their detection rules, keep threat-intelligence feeds current, and validate that incident-response runbooks are tested before an incident occurs.

Source: The Hacker News