Executive Summary
What if the software your IT team uses to protect and manage your computers became the very tool attackers used to take them over?
That is the concern behind a new ransomware campaign linked to Storm-1175, a financially motivated threat actor associated with China.
A previously undocumented ransomware strain called StormEncryptor has been identified, marking a shift from the group's previous use of Medusa ransomware. More concerning is the suspected route into victim networks: attackers likely exploited a vulnerability in N-able N-central, a remote monitoring and management platform used by IT teams and Managed Service Providers (MSPs) to remotely manage servers, computers, and other devices.


Storm-1175 has historically been associated with high-speed ransomware operations and has previously exploited vulnerabilities in products including Mirth Connect, ConnectWise ScreenConnect, JetBrains TeamCity, Fortinet FortiClient EMS and Fortra GoAnywhere to deploy ransomware. This latest campaign introduces a new weapon into that playbook: StormEncryptor.
What Makes StormEncryptor Different?
StormEncryptor follows this familiar formula, but it represents a change in Storm-1175's operations. It was observed that the ransomware is written in C++ and adds the “.encrypted” extension to files it encrypts. It also leaves a ransom note named “!!!README_FIRST!!!.txt” in directories it scans.

Victims are reportedly given approximately three days to contact the attackers and negotiate, with the alternative being the publication of stolen data. This combines file encryption with data theft, a tactic commonly known as double extortion.
The compromise of an RMM(Remote Monitoring and Management) platform can have consequences far beyond a single server. For MSPs, the potential blast radius is even greater because one compromised management environment could provide a pathway into multiple customer environments.
What Is CVE-2026-18577?
The vulnerability at the center of this incident is CVE-2026-18577, a security flaw affecting N-able N-central (a platform that lets IT teams monitor, manage, protect, and fix computers, servers and networks remotely).

The vulnerability allows an attacker to bypass authentication that is, get past the normal login protection and obtain administrative control of vulnerable N-central servers. It was assigned a CVSS score of 8.2, placing it in the High severity category.
CVE-2026-18577 was not an isolated issue. It followed an earlier vulnerability, CVE-2026-18556, after the initial fix was found to be incomplete. CVE-2026-18577 was therefore described as a patch bypass, a way around the protection that was supposed to fix the original problem.
How Did the Attackers Move?
- Gain Initial Access: They exploited the N-central vulnerability to gain unauthorized administrative access. The exploitation occurred around the time the vulnerability was disclosed, highlighting how quickly the group can weaponize newly disclosed flaws.
- Establish Remote Access: Once inside, the attackers were observed abusing legitimate remote-management tools such as AnyDesk and SimpleHelp.
- Discover the Network: The attackers used Advanced IP Scanner to identify systems and devices within the environment.
- Steal Credentials: Storm-1175 has also been observed using Mimikatz, a tool capable of extracting credentials from Windows systems.
- Steal Data: Before deploying ransomware, the attackers may exfiltrate sensitive information.
- Deploy StormEncryptor: The attackers deploy the ransomware, encrypt files and leave a ransom note demanding that victims contact them.
Why This Attack should concern Organizations
- A compromised employee laptop is a problem.
- A compromised management platform can be a much bigger problem.
- For an organization using an RMM platform, a successful compromise could potentially give attackers a path to multiple endpoints, servers and customer environments.
- For an MSP, the consequences can extend even further.
What Organizations Should Do Now
- Patch N-central Immediately: Organizations running self-hosted N-central environments should ensure that the latest security fixes have been applied.
- Check for Signs of Compromise:
Review:
- N-central authentication and administrative logs.
- Unexpected administrator accounts and deployment of software or scripts.
- Unusual remote-access activity and credential-access activity.
- Suspicious AnyDesk or SimpleHelp activity.
- Unexpected network scanning.
- Signs of Cloudflare-based tunnelling or the Cloudflared service.
- Unexpected svchost.exe files in user Documents folders.
- Protect Your Backups:
Ensure critical backups are:
- Regularly tested and properly protected.
- Not directly accessible using ordinary user credentials.
- Strengthen Access Controls:
Organizations should:
- Enforce Multi-Factor Authentication (MFA) where supported.
- Limit administrative access to trusted networks or authorized personnel.
- Remove unnecessary accounts and privileges.
- Monitor the Environment, not Just the Perimeter: Monitor for unusual administrative activity, unexpected remote-management sessions, credential theft, network discovery and abnormal file-encryption behaviour.
Conclusion
Storm-1175's latest campaign demonstrates how quickly a threat actor can move from exploiting a vulnerability to gaining access, exploring a network, stealing credentials, exfiltrating data and deploying ransomware. And when the compromised technology is a centralized management platform, the potential impact can extend far beyond one machine.
Follow esentry for more threat intelligence, emerging vulnerability alerts and practical security advisories designed to help organizations identify threats before they become incidents.

.jpeg)

.jpeg)


.png)

.png)
.png)