< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [CRIME]

2 clusters · 4 sources · 13 days · First seen · Last updated

Ransomware campaign and malware evolution

Overview

Cybersecurity researchers have identified distinct ransomware operations utilizing different social engineering and technical exploitation methods.

One campaign, tracked as STST4749, involves attackers using short Microsoft Teams voice or chat calls to impersonate IT help-desk staff. By persuading employees to approve remote-management tools, the operators deploy Chaos ransomware. This operation targeted numerous organizations in North America between February and June 2026, evolving from a custom loader to a Python-based backdoor to evade detection.

Separately, Microsoft Threat Intelligence identified StormEncryptor, a ransomware strain deployed by the China-based hacking group Storm-1175. This group has transitioned from being a Medusa ransomware affiliate to developing its own custom C++ malware. Storm-1175 focuses on exploiting unpatched systems, such as vulnerabilities in N-able N-central remote management software, to gain access and encrypt files.

Entities

Microsoft · N-able · Chaos ransomware · Sophos · Microsoft Teams

Timeline

  1. about 8 hours ago

    [TECHNOLOGY] 4 sources
    Microsoft identifies StormEncryptor ransomware from Chinese hacking group

    Microsoft has uncovered StormEncryptor, a new ransomware developed by the Chinese hacking group Storm-1175, which targets unpatched software to encrypt data and demand ransoms.

  2. 13 days ago

    [CRIME] 6 sources
    Microsoft Teams ransomware campaign encrypts networks via two‑minute calls

    Sophos reports a ransomware campaign (STST4749) using two‑minute Microsoft Teams calls to gain remote access and deploy Chaos ransomware across North American firms.

Sources

barbaraganz.blog.ilsole24ore.com · mediaindonesia.com · pemilu2024.harianjogja.com · uzone.id