Learn
archived
StormEncryptor ransomware deployed by ex-Medusa affiliate
- Engineer — Learn: A new ransomware strain from a Medusa affiliate signals an active threat actor pivoting to new tooling, but the thin summary provides no specific vulnerability, attack vector, or affected software to patch or harden against today.
- SOC/IR — Learn: Tracking a Medusa-lineage actor rebranding to StormEncryptor is useful triage context, but no IOCs, TTPs, or ATT&CK mappings are provided — file for actor awareness until a fuller technical report with detection surface emerges.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.