Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [CRIME]
2 clusters · 4 sources · 13 days · First seen · Last updated
Ransomware campaign and malware evolution
Overview
Cybersecurity researchers have identified distinct ransomware operations utilizing different social engineering and technical exploitation methods.
One campaign, tracked as STST4749, involves attackers using short Microsoft Teams voice or chat calls to impersonate IT help-desk staff. By persuading employees to approve remote-management tools, the operators deploy Chaos ransomware. This operation targeted numerous organizations in North America between February and June 2026, evolving from a custom loader to a Python-based backdoor to evade detection.
Separately, Microsoft Threat Intelligence identified StormEncryptor, a ransomware strain deployed by the China-based hacking group Storm-1175. This group has transitioned from being a Medusa ransomware affiliate to developing its own custom C++ malware. Storm-1175 focuses on exploiting unpatched systems, such as vulnerabilities in N-able N-central remote management software, to gain access and encrypt files.
Entities
Microsoft · N-able · Chaos ransomware · Sophos · Microsoft Teams
Timeline
-
about 8 hours ago
[TECHNOLOGY] 4 sourcesMicrosoft identifies StormEncryptor ransomware from Chinese hacking groupMicrosoft has uncovered StormEncryptor, a new ransomware developed by the Chinese hacking group Storm-1175, which targets unpatched software to encrypt data and demand ransoms.
-
13 days ago
[CRIME] 6 sourcesMicrosoft Teams ransomware campaign encrypts networks via two‑minute callsSophos reports a ransomware campaign (STST4749) using two‑minute Microsoft Teams calls to gain remote access and deploy Chaos ransomware across North American firms.
Sources
barbaraganz.blog.ilsole24ore.com · mediaindonesia.com · pemilu2024.harianjogja.com · uzone.id