A financially motivated threat actor linked to China is believed to be exploiting a critical vulnerability affecting widely used cybersecurity software in a supply-chain attack that could see the hackers deploy custom ransomware across a cascading list of victims’ networks.
Microsoft Threat Intelligence warned this weekend that the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor. The hackers previously used the Medusa ransomware to extort healthcare, professional services and finance organizations in Australia, Britain and the United States.
Back in April, the hackers were described as operating “high-velocity ransomware campaigns” exploiting both recently disclosed vulnerabilities and zero-day exploits, “in some cases a full week before public vulnerability disclosure.” Microsoft said it had seen the group move from initial access to full encryption in under 24 hours.
In this latest campaign, Microsoft said the group is likely exploiting CVE-2026-18577 — a vulnerability in N-central, a remote monitoring and management (RMM) console used by thousands of managed service providers to administer client endpoints.
Microsoft has not formally confirmed the access vector, but noted that StormEncryptor deployments began the same day the flaw was disclosed. The vulnerability gives attackers “unauthenticated, ‘god-mode’ access,” the cybersecurity firm Huntress warned.
Practically, it allows attackers with no credentials whatsoever to gain full administrative control of an N-central server. Because MSPs use N-central to remotely manage their clients’ machines, that single compromised server becomes a gateway to every endpoint it controls. One breach at one provider can cascade into dozens of ransomware incidents across its entire client base.
In 2021, a similar supply-chain attack on an RMM tool from software provider Kaseya allowed the REvil ransomware gang to initially compromise 60 of Kaseya’s direct customers before subsequently hitting around 1,500 downstream businesses.
Another supply-chain attack in 2024 — again on an RMM — impacted ConnectWise’s ScreenConnect product. It similarly led to numerous downstream ransomware attacks. Microsoft said Storm-1175 was among the multiple threat actors targeting ScreenConnect at the time.
A rough count of impacted organizations has not been disclosed. N-able, the software company behind N-central, said it has contacted a “limited number” of affected customers. Huntress confirmed some of its own customers were impacted and published a timeline showing attackers moving rapidly across downstream hosts in two incidents, but again did not confirm how many downstream entities faced ransomware attacks.
N-able said the vulnerability behind the campaign was first detected in a zero-day attack on July 31 — although it is unclear whether the threat actor behind that initial attack was Storm-1175. The initial flaw proved difficult to fix. N-able said the attackers found a way around an initial patch and shipped an emergency hotfix on August 2 before then issuing a second emergency hotfix on August 6, warning customers the first was not enough.
Even after the patches were available, Huntress said it found more than half of reachable N-central cloud servers across its partner base were still unpatched, with 28.6% of self-hosted instances remaining exposed.
Huntress said that anyone running N-central in a “higher-risk” environment “where you cannot meaningfully reduce exposure” may need to consider turning the tool off. However, it cautioned “taking N-central offline means losing central visibility, patching, and remote access when they may be needed most.”
Recorded Future
Intelligence Cloud.
Learn more.
