Cyber Resilience
← All news
Corroborated

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Our takeMicrosoft reports that China-linked Storm-1175, a former Medusa affiliate, is now deploying its own StormEncryptor ransomware, likely via an N-central flaw. Patch N-central and watch for .encrypted files if you run it.
Sources (2)
What this means for you — Security leader:Patch N-central instances immediately and review logs for Storm-1175 activity; block outbound C2 and monitor for .encrypted file extensions.
What this means for you — Lean IT orgs:If you use N-central to manage your systems, contact your provider today to confirm they have patched it and are watching for this ransomware.
What this means for you — MSP:Prioritize patching all N-central servers across client estates; deploy detection for StormEncryptor and associated Storm-1175 C2 patterns.
What this means for you — Researcher:Track Storm-1175 TTPs and StormEncryptor binary artifacts; compare against prior Medusa campaigns for overlaps in tooling and infrastructure.