CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

New StormEncryptor ransomware used by former Medusa affiliate

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4159

As cited

Citation snapshot as of .

ransomware

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor with previous ties to the Medusa ransomware group has begun deploying a new ransomware variant called StormEncryptor. The shift suggests continued evolution within the ransomware-as-a-service ecosystem as operators adopt new tools and infrastructure.

Why it matters: Organizations previously targeted by Medusa affiliates face elevated risk from this new payload; security teams should monitor for StormEncryptor indicators of compromise and update detection rules accordingly.

Source published
First seen by Cybersecurity Tracker

Source attribution