Key Takeaways
- Storm-1175, a financially motivated Chinese-linked threat actor, has deployed a new ransomware strain called StormEncryptor since August 2, 2025.
- The group is exploiting CVE‑2026‑18577, a critical “god‑mode” zero‑day vulnerability in N‑central, the remote monitoring and management (RMM) platform used by many managed service providers (MSPs).
- Because N‑central gives attackers unauthenticated full administrative control, compromising a single MSP server can cascade into ransomware infections across dozens or hundreds of client networks.
- Historical precedents (Kaseya 2021, ConnectWise ScreenConnect 2024) show similar supply‑chain RMM attacks can affect thousands of downstream organizations.
- Although N‑able released emergency hotfixes on August 2 and August 6, a significant portion of N‑central instances remain unpatched, leaving many organizations exposed.
- Security experts advise urgent patching, network segmentation, and, in high‑risk environments where exposure cannot be reduced, consideration of temporarily disabling N‑central while accepting the loss of centralized visibility and remote‑access capabilities.
Threat Actor Background
Storm-1175 is a financially motivated cyber‑crime group that security researchers have linked to China‑based operations. The actor first gained notoriety for using the Medusa ransomware to target healthcare, professional services, and finance firms in Australia, the United Kingdom, and the United States. Microsoft Threat Intelligence has described the group’s tactics as “high‑velocity ransomware campaigns,” noting its ability to move from initial access to full encryption in under 24 hours. The group’s pattern includes exploiting newly disclosed vulnerabilities and, in some cases, zero‑day flaws before they are publicly announced, giving it a decisive advantage over defenders.
Emergence of StormEncryptor
On August 2, 2025, Microsoft warned that Storm-1175 began deploying a novel ransomware variant dubbed StormEncryptor. This marks a shift from the group’s previous reliance on Medusa, indicating an effort to evolve its payload arsenal and potentially evade existing detection signatures. The timing of the StormEncryptor rollout coincides precisely with the public disclosure of a critical flaw in N‑central, suggesting that the vulnerability served as the initial access vector for the new campaign.
Exploited Vulnerability: CVE‑2026‑18577
The flaw tracked as CVE‑2026-18577 resides in N‑central, a widely adopted remote monitoring and management console produced by N‑able. Huntress researchers characterized the vulnerability as providing “unauthenticated, ‘god‑mode’ access,” meaning an attacker equipped with no credentials can obtain full administrative control over an N‑central server. Since MSPs rely on N‑central to remotely manage and patch client endpoints, a compromised server becomes a potent pivot point, enabling the attacker to push malicious code—such as StormEncryptor—to every device under the MSP’s oversight.
Supply‑Chain Propagation Mechanism
When an MSP’s N‑central instance is hijacked, the attacker can issue commands that execute ransomware across all managed machines. This creates a cascading effect: a single breach at one provider can trigger dozens, hundreds, or even thousands of downstream ransomware incidents. The scenario mirrors earlier supply‑chain attacks, such as the 2021 Kaseya incident where REvil initially compromised 60 direct customers and subsequently impacted roughly 1,500 downstream businesses, and the 2024 ConnectWise ScreenConnect breach that similarly proliferated ransomware through an RMM channel.
Historical Context of RMM‑Focused Attacks
Storm-1175’s current activity is not isolated; the group was identified among multiple threat actors targeting ConnectWise’s ScreenConnect product during the 2024 incident. These episodes underscore a growing trend where adversaries prioritize RMM platforms as high‑value targets due to their privileged positioning within customer IT environments. The recurrence of such attacks highlights the systemic risk posed by centralized management tools when they are not adequately hardened or promptly patched.
Patch Response and Remaining Exposure
N‑able first detected the zero‑day exploit on July 31, 2025, and issued an emergency hotfix on August 2. However, attackers quickly bypassed that patch, prompting N‑able to release a second emergency hotfix on August 6, warning that the initial fix was insufficient. Despite the availability of updates, Huntress reported that more than half of reachable N‑central cloud servers within its partner base remained unpatched, with 28.6% of self‑hosted instances still exposed. This lag in remediation leaves a substantial attack surface open for exploitation.
Mitigation Recommendations
Security advisors urge organizations using N‑central to apply the latest hotfixes immediately and to verify patch compliance across all deployments. Network segmentation—isolating the N‑central server from critical assets and limiting lateral movement—can reduce the impact of a potential compromise. In environments where exposure cannot be meaningfully reduced (e.g., where the MSP cannot afford downtime), Huntress suggests considering a temporary shutdown of N‑central, acknowledging that doing so sacrifices centralized visibility, patching, and remote‑access capabilities precisely when they may be most needed. Complementary measures include enforcing multifactor authentication for administrative accounts, monitoring for anomalous privileged‑access behavior, and maintaining robust offline backups to facilitate recovery without paying ransom.
Conclusion
The Storm-1175 group’s adoption of StormEncryptor and its exploitation of CVE‑2026-18577 illustrate the dangerous convergence of financially motivated cybercrime, zero‑day vulnerabilities, and the inherent trust placed in RMM solutions. By compromising a single N‑central server, threat actors can unlock a pathway to extensive ransomware deployment across numerous client networks, echoing the scale seen in prior supply‑chain attacks on Kaseya and ConnectWise. While patches are available, the persistent gap in update adoption underscores the need for urgent remediation, proactive monitoring, and strategic risk‑management practices to defend against increasingly swift and destructive ransomware campaigns.

