Microsoft Threat Intelligence has issued a warning about Storm-1175, a financially motivated, China-linked threat actor, actively exploiting a critical vulnerability in N-able N-central remote monitoring and management (RMM) software. The vulnerability, CVE-2026-18577, is an authentication bypass that grants attackers administrative control over N-central servers. Storm-1175 is leveraging this access to deploy a new, custom C++ ransomware variant called StormEncryptor. This campaign represents a severe supply-chain threat, as compromising a single Managed Service Provider's (MSP) N-central server allows the attacker to push ransomware to all of that MSP's downstream clients. Due to active exploitation, CISA has added CVE-2026-18577 to its Known Exploited Vulnerabilities (KEV) catalog.
The campaign began on August 2, 2026, the same day the vulnerability was disclosed. Storm-1175 demonstrated its characteristic speed by weaponizing the flaw almost immediately. The attack targets MSPs that use N-able's N-central RMM platform to manage customer environments. The core of the attack is the exploitation of CVE-2026-18577, which stems from an incomplete patch for a previous flaw, CVE-2026-18556.
The attack chain is as follows:
T1190 - Exploit Public-Facing Application)T1219 - Remote Access Software)T1071.001 - Web Protocols)T1486 - Data Encrypted for Impact)This campaign marks a tactical evolution for Storm-1175, which was previously associated with deploying Medusa ransomware.
.encrypted extension to files and drops a ransom note named !!!README_FIRST!!!.txt.This attack poses a critical supply-chain risk. By targeting MSPs, Storm-1175 can achieve a high-leverage, one-to-many attack model. The impact includes:
!!!README_FIRST!!!.txt*.encryptedSecurity teams, especially at MSPs, should hunt for the following patterns:
anydesk.exeadvanced_ip_scanner.execloudflared.exeN-central audit logsAnyDesk and Cloudflare Tunnel. Create alerts for their execution from unusual user accounts or directories. Employ Process Analysis (D3-PA).New TTPs including Mimikatz and Advanced IP Scanner identified in Storm-1175 attacks; N-able releases second hotfix for CVE-2026-18577.
The most critical mitigation is to apply the security patches provided by N-able to fix CVE-2026-18577.
Restrict network access to the N-central management interface to trusted IP addresses only, reducing the attack surface.
Closely monitor and audit all accounts with administrative privileges on RMM software. Implement MFA as a compensating control.
Use application allowlisting on managed endpoints to prevent the execution of unauthorized remote access tools like AnyDesk.
CVE-2026-18577 is publicly disclosed. Storm-1175 begins exploitation campaign on the same day.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.