Utopia Tech
SecurityAI-assisted1 min read

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has identified Storm-1175, a China-linked financially motivated threat actor, deploying a new ransomware variant called StormEncryptor, marking a shift from their previous use of Medusa ransomware. The C++-written malware appends the .encrypted extension to compromised files. This development represents an evolution in the threat actor's toolkit and operational capabilities.

UT

Utopia Tech

August 10, 2026 · 1 min read

Share

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content