Storm-1175 is back, and Microsoft says the ransomware crew has switched things up with a new strain called StormEncryptor. In a detailed post on X, Microsoft Threat Intelligence shared that the financially motivated group started deploying the malware on August 2, marking its first activity observed by Microsoft since April. The ransomware attacks are moving fastOnce inside a network, Storm-1175 reportedly relies on familiar administration tools for its operations. Microsoft observed the group using AnyDesk and SimpleHelp for remote access. Microsoft previously observed some attacks reaching ransomware deployment within a day.