China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Summary

A financially motivated threat actor, Storm-1135, which is linked to China, has begun deploying a new ransomware strain named StormEncryptor. This marks a departure from their previous use of the Medusa ransomware.

IFF Assessment

FOE

The emergence of a new ransomware strain deployed by a sophisticated threat actor is detrimental to cybersecurity defenders.

Defender Context

Defenders should be aware of this new ransomware, StormEncryptor, and the threat actor Storm-1175. The article mentions a potential initial access vector via a flaw in N-central, so organizations utilizing this software should ensure it is patched and monitored.

Read Full Story →