New StormEncryptor ransomware used by former Medusa affiliate
… N-able previously recommended admins to check for signs of compromise such as an svchost.exe file in the Documents folders of users' device, a registered service named Cloudflared, and inbound connections from the IP addresses listed in the advisory. …