Microsoft said the financially motivated, China-linked threat actor Storm-1175 is using CVE-2026-18577, a critical authentication-bypass flaw in N-able N-central, to deploy a new ransomware strain called StormEncryptor. The activity began around July 31, with Microsoft observing ransomware deployments from August 2, the same day the vulnerability was publicly disclosed. The flaw can give unauthenticated attackers full administrative control of N-central servers, raising supply-chain concerns because managed service providers use the platform to manage large numbers of downstream customer endpoints.
The campaign marks Storm-1175’s first observed activity since April and a shift from its earlier association with Medusa to a custom C++ encryptor. Microsoft observed the group using AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for remote access, network discovery, credential theft, and hands-on-keyboard deployment. StormEncryptor appends the .encrypted extension to files and drops ransom notes named !!!README_FIRST!!!.txt. N-able released multiple emergency fixes after attackers bypassed an initial patch, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, and Huntress warned that many internet-exposed N-central instances remained unpatched.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On August 6, 2026, N-able issued a second emergency hotfix and warned customers that the first fix was insufficient after attackers found a way around the initial patch. The company also said it had contacted a limited number of affected customers.
CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog on August 3, 2026. The listing reflected active exploitation concerns around the N-able vulnerability.
N-able released an emergency hotfix on August 2, 2026 to address CVE-2026-18577 in N-central. The flaw could give unauthenticated administrative control over affected servers.
The authentication-bypass vulnerability CVE-2026-18577 affecting N-able products was publicly disclosed on August 2, 2026. Microsoft noted StormEncryptor activity was observed the same day the flaw became public.
Microsoft Threat Intelligence observed Storm-1175 begin deploying the previously undocumented StormEncryptor ransomware on August 2, 2026. Microsoft said this was the group's first observed activity since April 2026 and assessed the campaign may be tied to exploitation of CVE-2026-18577.
N-able said CVE-2026-18577 was first detected in a zero-day attack on N-central on July 31, 2026. The company said it was unclear whether Storm-1175 was responsible for that initial exploitation.
Guidance from CERT.UG and N-able described attackers using CVE-2026-18577 to take over N-central servers, pivot to managed customer endpoints through Take Control, and install persistent Cloudflare tunnels as Windows services. The notice also published endpoint indicators such as svchost.exe in user Documents folders and a Cloudflared service.
Microsoft Threat Intelligence said Storm-1175, a threat actor previously associated with Medusa ransomware, had shifted to deploying a new ransomware strain called StormEncryptor. Microsoft also assessed the actor to be China-based and published technical details on the malware and post-compromise tooling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecysecurity.news
Open sourcecert.ug
Open sourcemkd-cirt.mk
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourcecyberveille.ch
Open sourcegbhackers.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.