StormEncryptor ransomware has emerged as a new cyber threat, used by a China-linked hacking group known as Storm-1175. Microsoft researchers have identified that this advanced ransomware is being deployed in attacks likely leveraging a vulnerability in N-able’s N-central remote monitoring and management (RMM) platform. The incident highlights an escalating risk for organisations that rely on managed service providers (MSPs), especially those using N-central, and underscores the growing sophistication of ransomware operations targeting supply chains.
StormEncryptor Ransomware: New Strain Linked to Storm-1175
First publicly disclosed in August 2026, StormEncryptor ransomware is attributed to Storm-1175, a financially motivated threat group linked to China. This group was previously known for deploying the Medusa ransomware. According to the Microsoft Threat Intelligence Team, Storm-1175’s switch to StormEncryptor marks a notable change in tactics and tooling, emphasising ongoing innovation among ransomware actors.
StormEncryptor is developed in C++, distinguishing it from earlier variants. Microsoft’s analysis found that encrypted files were appended with the “.encrypted” extension, a clear sign of compromise. The ransomware is designed for rapid deployment, likely benefiting from automation and customisation options tailored to different victims.
Attack Timeline and Exploitation Methodology
The attacks involving StormEncryptor were first observed in late July 2026. Microsoft’s telemetry indicated a sharp increase in exploitation attempts around this time, particularly targeting organisations managed by MSPs. The attackers are believed to be exploiting a then-unpatched vulnerability in N-able’s N-central RMM platform. N-central is widely used by MSPs to provide IT management services to small and midsize businesses, making it an attractive target for supply chain attacks.
The attack chain appears to involve the following steps:
- Reconnaissance of MSPs and their managed client infrastructure
- Exploitation of an N-central vulnerability to gain initial access
- Deployment of StormEncryptor ransomware to compromised endpoints
- File encryption and appending of the “.encrypted” extension
- Ransom note delivery demanding cryptocurrency payment
Microsoft has not publicly disclosed the technical details of the N-central flaw, citing ongoing investigations. However, the company strongly suspects Storm-1175 is using a remote code execution or privilege escalation vulnerability to gain persistent access to MSP networks. Once inside, attackers are able to pivot across multiple client environments, amplifying the impact of a single breach.
Scope of Impact and Targeted Organisations
The primary victims of the StormEncryptor campaign are SMBs managed by MSPs using N-central. Organisations relying on external IT management are at heightened risk, especially if their MSPs have not applied N-central security updates or implemented robust access controls. The supply chain nature of this attack allows Storm-1175 to compromise dozens or even hundreds of businesses via a single vulnerable MSP.
StormEncryptor’s impact is significant due to its rapid file encryption, targeting of shared drives and backups, and the disruption caused to business operations. Microsoft’s incident response teams have observed:
- Encrypted data across Windows endpoints managed via N-central
- Compromised administrative credentials used for lateral movement
- Ransom demands tailored to the victim’s perceived ability to pay
- Attempts to disable security tools before encryption begins
The ongoing exploitation has made this campaign one of the most prominent ransomware threats of the summer 2026 period.
Current Exploitation Status and Response
As of early August 2026, exploitation of the suspected N-central vulnerability remains active. Microsoft continues to track Storm-1175’s operations and has shared relevant indicators of compromise (IOCs) with the security community. N-able has issued security advisories, and patches are available for supported versions of N-central. However, exploitation attempts are ongoing against unpatched systems, and organisations are urged to apply updates immediately.
Microsoft has also recommended that MSPs:
- Review and restrict privileged access within N-central
- Implement multi-factor authentication for all administrative logins
- Monitor for anomalous activity, such as mass file encryption or unexpected remote connections
The threat actor’s shift from Medusa to StormEncryptor demonstrates a willingness to evolve tools and tactics, increasing the urgency for swift defensive action. No decryption tool is currently available for StormEncryptor, and victims are left with limited options aside from restoring from clean backups or negotiating with attackers.
Why This StormEncryptor Attack Matters
This campaign is significant because it targets the supply chain via widely used MSP platforms, multiplying the potential impact. A single exploited MSP can lead to ransomware across many client environments, resulting in widespread operational disruption. The tactic of exploiting RMM software weaknesses is becoming more common among financially motivated groups, raising the stakes for both service providers and their customers.
Immediate Recommendations for Organisations
Organisations using N-central, either directly or via an MSP, should:
- Ensure all N-central instances are updated to the latest secure version
- Work with MSPs to audit privileged access and monitor for suspicious activity
- Review ransomware incident response plans and confirm offline backups are available
Rapid action can mitigate the risk from StormEncryptor and reduce the chances of severe business disruption.
Originally reported by thehackernews.com.







