supply-chaintrade-pressNewsThe Broadside1 min read

Storm-1175 exploits N-central bug to push ransomware through MSPs

The third RMM supply-chain ransomware cascade in four years, and a patching gap north of 50%, suggest this attack class has hardened from anomaly to durable threat, and defenders haven't caught up.


TL;DR

Storm-1175, a financially motivated China-linked group, is exploiting CVE-2026-18577 in N-able's N-central RMM to deploy StormEncryptor ransomware across MSP-managed downstream networks. The flaw provides unauthenticated administrative access to the management console. Huntress reports more than half of reachable N-central cloud instances remain unpatched even after N-able shipped a second emergency hotfix to close a bypass. The same group exploited the ScreenConnect RMM in 2024 and previously used Medusa ransomware before switching to its own custom strain.

The N-central compromise is the third time in four years that attackers have turned an RMM tool into a ransomware distribution platform. In 2021, REvil exploited a Kaseya VSA vulnerability to hit roughly 1,500 downstream businesses through 60 compromised MSPs. In 2024, multiple actors, including Storm-1175, exploited ConnectWise ScreenConnect to run ransomware against managed clients. Now N-central joins the list.

The mechanics are identical each time: a critical auth-bypass or code-execution flaw in the RMM console gives attackers administrative control of the MSP's management plane, which by design has trusted access to every client endpoint. One breach, dozens or hundreds of downstream victims. The architecture that makes MSPs efficient makes them force-multipliers for ransomware.

The patching gap

N-able's response illustrates how brittle the defense side remains. The company detected a zero-day attack on July 31, shipped a hotfix, then discovered attackers had bypassed it and shipped a second emergency hotfix on August 6. Even after both fixes, Huntress found more than half of reachable N-central cloud instances unpatched and 28.6% of self-hosted instances still exposed. Huntress advised some customers to consider taking N-central offline, a measure that'd cost them remote visibility and patching capability precisely when they need both most.

Storm-1175's shift from Medusa to its own custom ransomware strain, StormEncryptor, suggests the group is investing in its toolchain rather than renting. Microsoft has tracked the group running "high-velocity ransomware campaigns" with dwell times under 24 hours from initial access to encryption. The move to an RMM supply-chain vector aligns with that speed: bypass credential theft and lateral movement entirely by seizing the management plane.


Published ·Deep Fathom

Storm-1175 exploits N-central bug to push ransomware through MSPs — The Broadside