New StormEncryptor ransomware used by former Medusa affiliate

Summary

A financially motivated threat actor, formerly linked to the Medusa ransomware operation, has begun deploying a new ransomware strain known as StormEncryptor. This development indicates a shift in tactics for affiliates transitioning to new tools while maintaining their malicious objectives.

IFF Assessment

FOE

The emergence of a new ransomware strain and its deployment by a known threat actor represents a direct threat to organizations and individuals, increasing the risk of data encryption and extortion.

Defender Context

Defenders should be aware of this new ransomware strain and the potential for former Medusa affiliates to use it. Monitoring for indicators of compromise associated with StormEncryptor and reinforcing general ransomware defenses, such as robust backups and endpoint detection and response, is crucial.

Read Full Story →