Security

China-Linked Storm-1175 Exploited N-able Flaw the Same Day It Was Disclosed

Microsoft says the ransomware group weaponized an authentication bypass in N-able's N-central within hours of disclosure, deploying new C++ ransomware StormEncryptor and dumping credentials with Mimikatz.

P
By Priya Nair Security Correspondent
August 10, 2026 / Updated August 19, 2026 / 5 min read

Financially motivated hackers linked to China began deploying a new ransomware strain on August 2, possibly hours after exploiting a critical authentication bypass in N-able's remote monitoring and management software, Microsoft Threat Intelligence said Friday. The group, tracked as Storm-1175, returned with C++-based ransomware called StormEncryptor after several dormant months since April, marking a shift away from the Medusa ransomware that had thrust the group into the public eye.

Exploitation Outpaced the Patch

Microsoft said Storm-1175 likely exploited CVE-2026-18577, an authentication bypass in N-able's N-central product, on the same day the vulnerability was disclosed. N-able had first detected the actively exploited zero-day on July 31, and its initial patch proved incomplete — the later flaw, which allows a remote, unauthenticated attacker to gain administrative control of vulnerable RMM servers on-premises or in the cloud, was assigned a CVSS score of 8.2 and added to CISA's Known Exploited Vulnerabilities catalog a day after disclosure, according to Rapid7 and BankInfoSecurity.

"Storm-1175 is known to operate high-velocity ransomware campaigns that weaponize N-days, taking advantage of the window between vulnerability disclosure and patch adoption," Microsoft said. "Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible." The group moves from initial access to data exfiltration and encryption within days — sometimes under 24 hours — abusing AnyDesk or SimpleHelp remote access tools, Advanced IP Scanner for discovery, and Mimikatz to dump credentials from LSASS process memory, which can grant domain-wide compromise.

Victims Listed, Data Posted in Three Days

A flurry of victim companies has appeared on Storm-1175's ransom site over the past week, spanning e-commerce, fintech, healthcare and home security. The ransomware encrypts files and drops a ransom note threatening to publish stolen data within three days. Microsoft says the group's post-compromise playbook also includes PsExec to reach domain controllers and exfiltrate Active Directory data — a reminder that the RMM tooling trusted for remote administration has become the top initial-access vector for fast-moving ransomware crews this quarter.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.