Critical cybersecurity update: China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.
What Happened
A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able. China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns | The Record from Recorded Future News China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns A financially motivated threat actor linked to China is believed to be exploiting a critical vulnerability affecting widely used cybersecurity software in a supply-chain attack that could see the hackers deploy custom ransomware across a cascading list of victims’ networks. Microsoft Threat Intelligence warned this weekend that the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor. The hackers previously used the Medusa ransomware to extort healthcare, professional services and finance organizations in Australia, Britain and the United States. Back in April, the hackers were described as operating “high-velocity ransomware campaigns” exploiting both recently disclosed vulnerabilities and zero-day exploits, “in some cases a full week before public vulnerability disclosure.” Microsoft said it had seen the group move from initial access to full encryption in under 24 hours. In this latest campaign, Microsoft said the group is likely exploiting CVE-2026-18577 — a vulnerability in N-central, a remote monitoring and management (RMM) console used by thousands of managed service providers to administer client endpoints. Microsoft has not formally confirmed the access vector, but noted that StormEncryptor deployments began the same day the flaw was disclosed. The vulnerability gives attackers “unauthenticated, ‘god-mode’ access,” the cybersecurity firm Huntress warned .
Technical Details
Practically, it allows attackers with no credentials whatsoever to gain full administrative control of an N-central server. Because MSPs use N-central to remotely manage their clients’ machines, that single compromised server becomes a gateway to every endpoint it controls. One breach at one provider can cascade into dozens of ransomware incidents across its entire client base. In 2021, a similar supply-chain attack on an RMM tool from software provider Kaseya allowed the REvil ransomware gang to initially compromise 60 of Kaseya’s direct customers before subsequently hitting around 1,500 downstream businesses. Another supply-chain attack in 2024 — again on an RMM — impacted ConnectWise's ScreenConnect product. It similarly led to numerous downstream ransomware attacks. Microsoft said Storm-1175 was among the multiple threat actors targeting ScreenConnect at the time. A rough count of impacted organizations has not been disclosed. N-able, the software company behind N-central, said it has contacted a “limited number” of affected customers.
Security Impact
Organizations using the affected technology should treat the report according to its critical severity classification. Huntress confirmed some of its own customers were impacted and published a timeline showing attackers moving rapidly across downstream hosts in two incidents, but again did not confirm how many downstream entities faced ransomware attacks. N-able said the vulnerability behind the campaign was first detected in a zero-day attack on July 31 — although it is unclear whether the threat actor behind that initial attack was Storm-1175. N-able said the attackers found a way around an initial patch and shipped an emergency hotfix on August 2 before then issuing a second emergency hotfix on August 6, warning customers the first was not enough. Even after the patches were available, Huntress said it found more than half of reachable N-central cloud servers across its partner base were still unpatched, with 28.6% of self-hosted instances remaining exposed. Huntress said that anyone running N-central in a “higher-risk” environment “where you cannot meaningfully reduce exposure” may need to consider turning the tool off. However, it cautioned “taking N-central offline means losing central visibility, patching, and remote access when they may be needed most.” is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes.
Recommended Actions
- Identify whether the affected product, service or software is present in the environment.
- Review the original vendor or research advisory and verify affected versions before making configuration changes.
- Apply vendor-provided security updates or mitigations as soon as operationally practical.
- Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
- Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.
Security Details
- Severity: Critical
- Original source: The Record
Why This Matters
Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.
Original Report
NetworkFix recommends reviewing the complete original report from The Record for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.