China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns

A financially motivated threat actor linked to China is believed to be exploiting a critical vulnerability affecting widely used cybersecurity software in a supply-chain attack that could see the hackers deploy custom ransomware across a cascading list of victims’ networks.
Microsoft Threat Intelligence warned this weekend that the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor. The hackers previously used the Medusa ransomware to extort healthcare, professional services and finance organizations in Australia, Britain and the United States.
Back in April, the hackers were described as operating “high-velocity ransomware campaigns” exploiting both recently disclosed vulnerabilities and zero-day exploits, “in some cases a full week before public vulnerability disclosure.” Microsoft said it had seen the group move from initial access to full encryption in under 24 hours.
In this latest campaign, Microsoft said the group is likely exploiting CVE-2026-18577 — a vulnerability in N-central, a remote monitoring and management (RMM) console used by thousands of managed service providers to administer client endpoints.
Microsoft has not formally confirmed the access vector, but noted that StormEncryptor deployments began the same day the flaw was disclosed. The vulnerability gives attackers “unauthenticated, ‘god-mode’ access,” the cybersecurity firm Huntress warned.
Practically, it allows attackers with no credentials whatsoever to gain full administrative control of an N-central server. Because MSPs use N-central to remotely manage their clients’ machines, that single compromised server becomes a gateway to every endpoint it controls. One breach at one provider can cascade into dozens of ransomware incidents across its entire client base.
In 2021, a similar supply-chain attack on an RMM tool from software provider Kaseya allowed the REvil ransomware gang to initially compromise 60 of Kaseya’s direct customers before subsequently hitting around 1,500 downstream businesses.
Another supply-chain attack in 2024 — again on an RMM — impacted ConnectWise's ScreenConnect product. It similarly led to numerous downstream ransomware attacks. Microsoft said Storm-1175 was among the multiple threat actors targeting ScreenConnect at the time.
A rough count of impacted organizations has not been disclosed. N-able, the software company behind N-central, said it has contacted a “limited number” of affected customers. Huntress confirmed some of its own customers were impacted and published a timeline showing attackers moving rapidly across downstream hosts in two incidents, but again did not confirm how many downstream entities faced ransomware attacks.
N-able said the vulnerability behind the campaign was first detected in a zero-day attack on July 31 — although it is unclear whether the threat actor behind that initial attack was Storm-1175. The initial flaw proved difficult to fix. N-able said the attackers found a way around an initial patch and shipped an emergency hotfix on August 2 before then issuing a second emergency hotfix on August 6, warning customers the first was not enough.
Even after the patches were available, Huntress said it found more than half of reachable N-central cloud servers across its partner base were still unpatched, with 28.6% of self-hosted instances remaining exposed.
Huntress said that anyone running N-central in a “higher-risk” environment “where you cannot meaningfully reduce exposure” may need to consider turning the tool off. However, it cautioned “taking N-central offline means losing central visibility, patching, and remote access when they may be needed most.”
References in this story
- Microsoft Threat Intelligence (@threatintel.microsoft.com) bsky.app On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
- Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations | Microsoft Security… www.microsoft.com The financially motivated cybercriminal threat actor Storm-1175 operates high-velocity ransomware campaigns that weaponize recently disclosed vulnerabilities to obtain initial access, exfiltrate data, and deploy Medusa…
- www.cve.org
- Critical N-able N-central Vulnerability and Active Exploitation | Huntress www.huntress.com Critical vulnerability in N-able N-central gives attackers unauthenticated, "god-mode" access to the RMM console.
- Kaseya: More than 1,500 downstream businesses impacted by ransomware attack therecord.media Florida-based software provider Kaseya said that fewer than 60 of its customers and fewer than 1,500 downstream businesses have been impacted by the ransomware attack that took place last Friday, on July 2.
- Cybercriminal groups actively exploiting ‘catastrophic’ ScreenConnect bug therecord.media Researchers said that “attacks against both servers and client machines are currently underway” as attackers attempt to exploit the critical vulnerability.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Alex Martin (@AlexMartin) on X twitter.com UK Editor: @TheRecord_Media | Fellowship alumnus: @VirtualRoutes | @SkyNews | Agent: @NorthbankTalent
- Alexander Martin (@alexmartin.bsky.social) bsky.app Journalist covering cybersecurity and intelligence. UK Editor at The Record from Recorded Future News. Dad of two. 🏠 Sheffield 📧 [email protected] 📱 Signal: AlexanderMartin.79



