China-Linked Hackers Deploy New Ransomware Targeting U.S. Systems
Microsoft has identified a new ransomware strain, StormEncryptor, deployed by the China-linked threat actor Storm-1175. This group, known for its financially motivated cyber activities, has shifted from using Medusa ransomware to the newly discovered StormEncryptor. The ransomware appends '.encrypted' to files and leaves a ransom note in affected directories. The attack likely exploits a vulnerability in N-able N-central, a remote monitoring and management platform. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged this vulnerability as actively exploited, highlighting the ongoing threat to U.S. cybersecurity.