Summary
- Microsoft says Storm-1175 has shifted from Medusa to a newly observed ransomware strain named StormEncryptor.
- Microsoft assesses exploitation of N-central CVE-2026-18577 as the likely initial-access route, but the exact vulnerability used remains unconfirmed.
- N-able says attackers used unauthorised N-central access to reach managed endpoints and maintain persistence, reinforcing the downstream risk of compromised RMM platforms.
The exploitation of N-able’s N-central remote-monitoring platform has developed into a ransomware story, with Microsoft linking a previously undocumented encryptor to a financially motivated actor already associated with attacks on internet-facing enterprise software.
N-able disclosed at the end of July that attackers had exploited a previously unknown vulnerability in N-central to obtain remote administrative access without authentication. Once inside, the company said the attackers used N-central’s Take Control capability to connect to managed devices and installed Cloudflare tunnel services on endpoints to maintain access after their route through N-central was removed.
Cyber Insider previously reported how the attackers reached managed endpoints through N-central and later how N-able issued a second hotfix after continued monitoring identified a related attack path. N-able now says Hotfix 2, build 2026.3.1.10, supersedes the first fix and addresses the vulnerability path known to the company.
The new development is the ransomware activity attached to that intrusion cycle. Microsoft Threat Intelligence says Storm-1175, a financially motivated actor it tracks as China-based, has begun deploying a new ransomware strain called StormEncryptor. The group had previously been associated with Medusa ransomware and with rapid exploitation of vulnerabilities in exposed enterprise software.
The initial-access assessment needs careful qualification. Microsoft says the recent Storm-1175 activity likely involved exploitation of CVE-2026-18577 in N-central. It has not established that vulnerability as the definitive entry point in every observed StormEncryptor incident. The difference between “likely” and “confirmed” is material while N-able’s own investigation remains active.
N-able’s confirmed findings establish enough of the surrounding risk independently. The vendor says a limited number of customers were affected and that attackers used unauthorised N-central access to reach devices managed through the platform. It has also warned that applying the latest hotfix removes the known vulnerable route but does not remove an attacker who established persistence before patching.
That creates the characteristic downstream problem associated with compromises of remote-monitoring and management software. RMM platforms are intentionally designed to administer many endpoints from a central service. Their legitimate functions can include remote control, software deployment, scripting, account administration, and monitoring. When an attacker obtains equivalent authority, a compromise can cross the organisational boundary between a service provider and the customers whose systems it manages.
The ransomware connection increases the consequence without changing the underlying architecture. A central management product does not need to contain ransomware itself to become part of a ransomware attack chain. Access through the platform can give an operator a route to systems where separate tooling is then deployed, while the legitimate management relationship can make malicious activity harder to distinguish from authorised administration.
Storm-1175’s shift to StormEncryptor also illustrates the fluidity of ransomware branding. Microsoft has previously seen the actor deploy Medusa, but the group’s use of a new encryptor does not necessarily indicate a completely new criminal organisation. Threat actors can change ransomware families while retaining access methods, infrastructure preferences, or operational personnel.
N-able’s incident remains under investigation, and the vendor has said it intends to publish a fuller root-cause analysis when it can do so safely. Until that work is complete, the defensible position is narrower: unauthorised access to N-central is confirmed, downstream endpoint access is confirmed, StormEncryptor deployment by Storm-1175 is reported by Microsoft, and CVE-2026-18577 is assessed as a likely — not proven — route connecting the two.




