← Back to feed
Breaches & RansomwareEmerging1 sourceAug 13, 2026 · 08:09via Security Affairs

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Brief

Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks.

Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the . encrypted extension, then leaves a !!! README_FIRST!!!. txt ransom note in each scanned directory.

The change suggests an evolution in the group’s ransomware operations.

Read more on Security Affairs