As cited
Citation snapshot as of .
ransomware
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor with previous ties to the Medusa ransomware group has begun deploying a new ransomware variant called StormEncryptor. The shift suggests continued evolution within the ransomware-as-a-service ecosystem as operators adopt new tools and infrastructure.
Why it matters: Organizations previously targeted by Medusa affiliates face elevated risk from this new payload; security teams should monitor for StormEncryptor indicators of compromise and update detection rules accordingly.
- Source published
- First seen by Cybersecurity Tracker