# Ransomware campaign and malware evolution

> Live situation record from CLSTR: https://clstr.news/situations/ransomware-campaign-and-malware-evolution
> Updated: 2026-08-12T00:06:30.000Z. Sources: 4. Developments: 2.

Cybersecurity researchers have identified distinct ransomware operations utilizing different social engineering and technical exploitation methods.

One campaign, tracked as STST4749, involves attackers using short Microsoft Teams voice or chat calls to impersonate IT help-desk staff. By persuading employees to approve remote-management tools, the operators deploy Chaos ransomware. This operation targeted numerous organizations in North America between February and June 2026, evolving from a custom loader to a Python-based backdoor to evade detection.

Separately, Microsoft Threat Intelligence identified StormEncryptor, a ransomware strain deployed by the China-based hacking group Storm-1175. This group has transitioned from being a Medusa ransomware affiliate to developing its own custom C++ malware. Storm-1175 focuses on exploiting unpatched systems, such as vulnerabilities in N-able N-central remote management software, to gain access and encrypt files.

## Timeline

### 2026-08-12: Microsoft identifies StormEncryptor ransomware from Chinese hacking group

Microsoft has uncovered StormEncryptor, a new ransomware developed by the Chinese hacking group Storm-1175, which targets unpatched software to encrypt data and demand ransoms.

4 sources. https://clstr.news/cluster/microsoft-identifies-stormencryptor-ransomware-from-chinese-hacking-group

### 2026-07-30: Microsoft Teams ransomware campaign encrypts networks via two‑minute calls

Sophos reports a ransomware campaign (STST4749) using two‑minute Microsoft Teams calls to gain remote access and deploy Chaos ransomware across North American firms.

6 sources. https://clstr.news/cluster/microsoft-teams-ransomware-campaign-encrypts-networks-via-twominute-calls

---
Cite as: Ransomware campaign and malware evolution. CLSTR, https://clstr.news/situations/ransomware-campaign-and-malware-evolution
