Redmond, Washington — August 10, 2026 — Microsoft Threat Intelligence has warned that Storm-1175, a financially motivated threat actor linked to China, began deploying a previously undocumented ransomware strain called StormEncryptor on August 2, 2026. The activity marks the group’s first operation observed by Microsoft since April and represents a shift away from the Medusa ransomware previously associated with its campaigns.
Microsoft has not confirmed the vulnerability used to obtain initial access during the new campaign. Its current assessment is that Storm-1175 may be exploiting CVE-2026-18577, an authentication-bypass vulnerability affecting N-able N-central. The flaw was publicly disclosed on August 2, the same day Microsoft began observing StormEncryptor deployments, and CISA added it to the Known Exploited Vulnerabilities Catalog on August 3.
N-central is a remote monitoring and management platform used by managed service providers and information technology departments to administer connected devices. A compromised N-central server can create access to systems throughout its managed environment, giving an attacker a path from the central console to customer endpoints.
That architecture creates a serious cascading risk. Compromise of one managed service provider does not automatically establish that every connected customer has been breached, but the access available through a central management platform can allow an attacker to reach multiple downstream environments from a single initial intrusion.
N-able reported that its Adlumin managed detection and response service detected unusual activity in a customer environment on July 31. The investigation identified a threat actor actively exploiting a zero-day vulnerability in an N-central server. N-able determined that servers running versions earlier than 2026.3.1.7 were vulnerable to remote administrative access.
The company released N-central 2026.3 Hotfix 1, build 2026.3.1.7, on August 2. Continued monitoring led N-able to issue Hotfix 2, build 2026.3.1.10, on August 6 with additional hardening measures. Hotfix 2 supersedes the first release and remains required for on-premises environments, including systems that already received Hotfix 1.
N-able has applied mitigations to its hosted N-central environments and stated that customers using those hosted instances do not need to perform a separate server update. Organizations operating on-premises N-central servers must upgrade to build 2026.3.1.10 immediately.
CVE-2026-18577 resulted from an incomplete correction for CVE-2026-18556, an earlier N-central authentication-bypass vulnerability addressed in version 2026.2. The new attack path demonstrated that the original correction did not close every route through which an attacker could obtain administrative control.
N-able determined that the attacker used administrative access to activate the platform’s Take Control feature and connect to devices inside the managed environment. After reaching those systems, the attacker registered a new service for a Cloudflare tunnel, preserving access after control of the original N-central server had been revoked.
The ability to remain connected after the central server is secured means that applying Hotfix 2 cannot be treated as proof that an affected environment is clean. Organizations must determine whether an attacker entered before remediation, reached managed endpoints, installed a tunneling service, created accounts, stole credentials, altered configurations, or established another persistence mechanism.
Microsoft reported that Storm-1175 used AnyDesk or SimpleHelp for remote access after compromise, Advanced IP Scanner to identify systems and Mimikatz to dump credentials from the Local Security Authority Subsystem Service. Access to LSASS memory can expose authentication material that may allow an attacker to expand privileges or move into additional systems.
Storm-1175 is known for high-velocity ransomware operations that exploit the period between vulnerability disclosure and widespread remediation. Microsoft has observed the actor progressing from initial access to data exfiltration and ransomware deployment within a few days, leaving defenders with a narrow opportunity to identify and contain the intrusion.
StormEncryptor is written in C++ and adds the .encrypted extension to files it encrypts. The ransomware places a note named !!!README_FIRST!!!.txt in every directory it scans. Microsoft Defender Antivirus identifies the known sample as Ransom:Win64/StormEncryptor, associated with SHA-256 hash c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054.
Microsoft Defender for Endpoint can detect connected activity through alerts that include “Hands-on-keyboard attack involving multiple devices” and “Potential human-operated malicious activity.” Those detections are important because the operation combines ransomware with legitimate administrative software that may not appear malicious when examined without context.
N-able has identified a limited number of affected customers and stated that its support teams contacted them directly. Neither Microsoft nor N-able has disclosed the total number of compromised managed service providers, downstream organizations, encrypted systems, ransom demands, or confirmed data-theft incidents associated with StormEncryptor.
N-able has released ten IP-address indicators connected to the attacks and a custom service template designed to check Windows endpoints for known indicators. The company cautioned that a clean result does not guarantee that an environment was unaffected because the detection template covers only the indicators currently known.
Organizations should examine user Documents folders for an unexpected svchost.exe file and check for a registered service named Cloudflared. Security teams should also review firewall records for the indicators identified by N-able, inspect Take Control activity, investigate unfamiliar AnyDesk or SimpleHelp deployments, examine Advanced IP Scanner execution and search for Mimikatz or LSASS-access activity.
Logs and evidence should be preserved before compromised systems are rebuilt or removed from service. Security teams should review the full period during which the N-central server remained exposed, invalidate suspicious sessions, rotate potentially compromised credentials and determine whether unauthorized access extended into customer endpoints.
CISA’s inclusion of CVE-2026-18577 in the Known Exploited Vulnerabilities Catalog confirms active exploitation of the flaw, but it does not establish that Storm-1175 conducted every observed N-central intrusion. Microsoft’s connection between the vulnerability and StormEncryptor remains an assessment rather than a confirmed initial-access finding.
The distinction is important because N-able detected exploitation before the vulnerability was publicly disclosed, and the company has not publicly attributed the July 31 zero-day activity to Storm-1175. Separate threat actors may exploit the same vulnerability once technical knowledge spreads and vulnerable servers remain accessible.
The immediate priority for on-premises N-central operators is installation of build 2026.3.1.10, followed by a compromise assessment covering the central server and every managed system the attacker could have reached. The administrative authority that makes remote management software valuable to service providers also makes a compromised console capable of turning one vulnerable server into a broad ransomware entry point.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



