China-Linked Hackers Exploit N-able Flaw in Ransomware Attacks | #ransomware | #cybercrime


Cybercrime
,
Fraud Management & Cybercrime
,
Incident & Breach Response

Microsoft Says Storm-1175 Exploited CVE-2026-18577 After Its Disclosure

Image: Shutterstock

Financially motivated hackers linked to China began deploying a new ransomware strain on Aug. 2, possibly after exploiting a critical vulnerability in N-able’s remote monitoring and management software.

See Also: Scattered Spider Exposed: Critical Takeaways for Cyber Defenders

The group, tracked as Storm-1175, is making a comeback with C++-based ransomware StormEncryptor after a few dormant months since April, Microsoft Threat Intelligence said Friday. The development marks a shift away from its previous Medusa ransomware that thrusted the group into the public eye.

The group’s post-compromise behavior this time includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery and Windows Local Security Authority Subsystem Service credential dumping using commodity credential theft tool Mimikatz, Microsoft said.

The threat actor moves rapidly between initial access to data exfiltration and ransomware deployment, often within a few days or even within 24 hours.

The attackers likely exploited an authentication bypass vulnerability, tracked as CVE-2026-18577, in network monitoring firm N-able’s product N-central, Microsoft said. Exploitation of the flaw happened on the same day as the disclosure.

N-central is widely used by managed security providers to monitor, patch and remotely access servers and endpoints for all their customers from a central platform, meaning hundreds or thousands of downstream systems across Asia-Pacific, Europe and the Americas can be impacted. Its users last week had to attempt to fend off a raft of hackers with a series of hot fixes published by Massachusetts-based N-able in the face of widespread exploitation of zero-days in the software (see: New N-able Zero Day Puts MSPs on Defensive).

“Storm-1175 is known to operate high-velocity ransomware campaigns that weaponize N-days, taking advantage of the window between vulnerability disclosure and patch adoption,” Microsoft said on social media platform Bluesky. “Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.”

N-able said it first detected the actively exploited zero-day on July 31. The company’s initial disclosure underestimated the scope of the impact, believing only on-premises servers were vulnerable. Its first patch was incomplete and failed to stop the attacks.

“On Aug. 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed,” said security intelligence firm Rapid7.

The later flaw was assigned a CVSS score of 8.2 on Aug. 2 and added to the U.S. Cybersecurity and Infrastructure Security Agency’s catalog of known exploited vulnerabilities a day after. It allows a remote, unauthenticated attacker to bypass authentication and obtain administrative control of all versions of vulnerable RMM servers both on-premises and in the cloud.

“Based on N-able’s advisory and the logs we and our partners have reviewed so far, we know that remote attackers can gain administrative access to vulnerable N-central servers and then abuse the built-in Take Control feature to pivot into managed endpoints and deploy Cloudflare-based tunnels for persistence,” said endpoint detection and response firm Huntress.

Although N-able issued two emergency hotfixes for the vulnerability, the ransomware group was fast to exploit unpatched deployments at some organizations. It encrypted files and dropped a ransom note that threatened to publish stolen data in three days.

A flurry of victim companies has been listed on Storm-1175’s ransom site throughout the past week, spanning industries including e-commerce, fintech, healthcare and home security.

The group’s latest activity echoes patterns from its previous operations under Medusa, such as maintaining persistence using RMM tools. The legitimate software often used by IT teams could also allow malicious parties to “create new user accounts, enable an alternative command-and-control (C2) method, deliver additional payloads, or use as an interactive remote desktop session,” Microsoft said in an April blog about Medusa.

The group is also known to use Mimikatz to dump credentials from LSASS process memory, which can store not only a current user’s OS credentials but also a domain administrator’s. Microsoft said this type of credential theft can allow attackers to compromise or encrypt an entire network, not just a single device.

Once the attackers obtain domain credentials, they can move laterally across the network using legitimate tools such as PsExec or Windows Management Instrumentation, or techniques such as pass-the-hash, which allows authentication without access to a user’s cleartext password.

With sufficient privileges, Storm-1175 can also use PsExec to reach a domain controller and steal Active Directory data containing user account information and password hashes that can be cracked offline. The attackers can also access security settings stored on the system, giving them greater visibility and control across the network.



Click Here For The Original Source.

——————————————————–

..........

.

.