CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

August 10, 2026

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw Ravie LakshmananAug 10, 2026Ransomware / Cybercrime Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts," Microsoft noted in a series of posts on Bluesky. "It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory." Although the exact vulnerability exploited by the threat actor as part of this campaign is unclear, the tech giant said it likely involves the…

CVEs: CVE-2026-18577, CVE-2026-18556, CVE-2023-37679, CVE-2023-43208, CVE-2024-1709, CVE-2024-1708, CVE-2024-27198, CVE-2024-27199, CVE-2023-48788, CVE-2025-10035