A new ransomware strain, known as StormEncryptor, has been deployed by Storm-1175, a financially motivated threat actor linked to China, according to a disclosure by Microsoft. This development marks a significant shift in the tactics employed by the adversary, which previously utilized Medusa ransomware.
The Microsoft Threat Intelligence Team has been monitoring the activities of Storm-1175, and their findings indicate that the group has adopted StormEncryptor as its new ransomware of choice. This change in strategy suggests that the threat actor is continually evolving and adapting its methods to achieve its objectives.
Technical details about StormEncryptor reveal that it is written in C++ and appends the file name extension ".encrypted" to compromised files. This information provides insight into the inner workings of the ransomware and may aid in the development of countermeasures to mitigate its impact.
The deployment of StormEncryptor by Storm-1175 is a notable development in the cybersecurity landscape, highlighting the ongoing threat posed by financially motivated threat actors. As these groups continue to innovate and expand their arsenals, it is essential for organizations to remain vigilant and proactive in their defense against such threats.
While the exact mechanisms used by Storm-1175 to distribute StormEncryptor are not specified, it is likely that the threat actor is exploiting vulnerabilities in software to gain access to targeted systems. The Microsoft disclosure serves as a reminder of the importance of keeping software up to date and patching vulnerabilities to prevent exploitation by malicious actors.
As the cybersecurity community continues to monitor the activities of Storm-1175 and the spread of StormEncryptor, it is crucial for organizations to prioritize their cybersecurity posture and implement robust defenses to protect against the evolving threat landscape.
<small>Source: The Hacker News — read the original story there.</small>