By Interestana AI Editorial — AI-drafted, human-overseen. How we report
China-Linked Storm-1175 Uses New StormEncryptor Ransomware

Microsoft's Threat Intelligence Team has revealed that a financially motivated threat actor identified as Storm-1175, which exhibits links to China, has begun deploying a novel ransomware strain designated StormEncryptor. This development signifies a tactical evolution for the adversary, as StormEncryptor replaces the previously utilized Medusa ransomware in their toolkit. The Microsoft report, published on June 11, 2024, details that StormEncryptor is developed in C++ and operates by appending the file extension ".encrypted" to all compromised files, rendering them inaccessible to the victim. This method is a common characteristic of ransomware attacks, aiming to extort payment for decryption keys.
The initial access vector for this campaign is strongly suspected to be a vulnerability within N-central, a remote monitoring and management (RMM) software solution. This inference is based on the threat actor's observed activities and the nature of the systems targeted. N-central is widely used by managed service providers (MSPs) to remotely manage and monitor their clients' IT infrastructure. Exploiting such a tool provides attackers with a broad reach, potentially allowing them to compromise numerous organizations through a single point of entry. The use of RMM software vulnerabilities is a growing trend among cybercriminals, as it offers significant leverage and efficiency in their operations.
Storm-1175 has been previously associated with various financially motivated cybercrime activities, including ransomware deployments. Their shift to StormEncryptor suggests a desire to enhance their capabilities or evade detection by employing new, potentially more sophisticated, malware. The specific functionalities and evasion techniques of StormEncryptor are still under active investigation by Microsoft and other cybersecurity researchers. However, the choice of C++ as the development language indicates a focus on performance and potentially lower-level system interaction, which can be advantageous for malware. The ".encrypted" file extension is a clear indicator of the ransomware's function.
This incident underscores the persistent threat posed by state-sponsored or state-linked cybercriminal groups to global businesses. The exploitation of RMM software highlights the critical importance of supply chain security and robust vulnerability management for all organizations, particularly those providing IT services. Managed Service Providers, in particular, are urged to ensure their N-central instances are patched and secured against known and potential zero-day exploits. The ongoing analysis by Microsoft aims to provide further insights into StormEncryptor's operational details and to develop effective countermeasures against Storm-1175's activities.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.