StormEncryptor Ransomware Targets N-central Flaw

China-linked group deploys new StormEncryptor ransomware via suspected N-central flaw

StormEncryptor ransomware has emerged as a new cyber threat, used by a China-linked hacking group known as Storm-1175. Microsoft researchers have identified that this advanced ransomware is being deployed in attacks likely leveraging a vulnerability in N-able’s N-central remote monitoring and management (RMM) platform. The incident highlights an escalating risk for organisations that rely on managed service providers (MSPs), especially those using N-central, and underscores the growing sophistication of ransomware operations targeting supply chains.

StormEncryptor Ransomware: New Strain Linked to Storm-1175

First publicly disclosed in August 2026, StormEncryptor ransomware is attributed to Storm-1175, a financially motivated threat group linked to China. This group was previously known for deploying the Medusa ransomware. According to the Microsoft Threat Intelligence Team, Storm-1175’s switch to StormEncryptor marks a notable change in tactics and tooling, emphasising ongoing innovation among ransomware actors.

StormEncryptor is developed in C++, distinguishing it from earlier variants. Microsoft’s analysis found that encrypted files were appended with the “.encrypted” extension, a clear sign of compromise. The ransomware is designed for rapid deployment, likely benefiting from automation and customisation options tailored to different victims.

Attack Timeline and Exploitation Methodology

The attacks involving StormEncryptor were first observed in late July 2026. Microsoft’s telemetry indicated a sharp increase in exploitation attempts around this time, particularly targeting organisations managed by MSPs. The attackers are believed to be exploiting a then-unpatched vulnerability in N-able’s N-central RMM platform. N-central is widely used by MSPs to provide IT management services to small and midsize businesses, making it an attractive target for supply chain attacks.

The attack chain appears to involve the following steps:

  • Reconnaissance of MSPs and their managed client infrastructure
  • Exploitation of an N-central vulnerability to gain initial access
  • Deployment of StormEncryptor ransomware to compromised endpoints
  • File encryption and appending of the “.encrypted” extension
  • Ransom note delivery demanding cryptocurrency payment

Microsoft has not publicly disclosed the technical details of the N-central flaw, citing ongoing investigations. However, the company strongly suspects Storm-1175 is using a remote code execution or privilege escalation vulnerability to gain persistent access to MSP networks. Once inside, attackers are able to pivot across multiple client environments, amplifying the impact of a single breach.

Scope of Impact and Targeted Organisations

The primary victims of the StormEncryptor campaign are SMBs managed by MSPs using N-central. Organisations relying on external IT management are at heightened risk, especially if their MSPs have not applied N-central security updates or implemented robust access controls. The supply chain nature of this attack allows Storm-1175 to compromise dozens or even hundreds of businesses via a single vulnerable MSP.

StormEncryptor’s impact is significant due to its rapid file encryption, targeting of shared drives and backups, and the disruption caused to business operations. Microsoft’s incident response teams have observed:

  • Encrypted data across Windows endpoints managed via N-central
  • Compromised administrative credentials used for lateral movement
  • Ransom demands tailored to the victim’s perceived ability to pay
  • Attempts to disable security tools before encryption begins

The ongoing exploitation has made this campaign one of the most prominent ransomware threats of the summer 2026 period.

Current Exploitation Status and Response

As of early August 2026, exploitation of the suspected N-central vulnerability remains active. Microsoft continues to track Storm-1175’s operations and has shared relevant indicators of compromise (IOCs) with the security community. N-able has issued security advisories, and patches are available for supported versions of N-central. However, exploitation attempts are ongoing against unpatched systems, and organisations are urged to apply updates immediately.

Microsoft has also recommended that MSPs:

  • Review and restrict privileged access within N-central
  • Implement multi-factor authentication for all administrative logins
  • Monitor for anomalous activity, such as mass file encryption or unexpected remote connections

The threat actor’s shift from Medusa to StormEncryptor demonstrates a willingness to evolve tools and tactics, increasing the urgency for swift defensive action. No decryption tool is currently available for StormEncryptor, and victims are left with limited options aside from restoring from clean backups or negotiating with attackers.

Why This StormEncryptor Attack Matters

This campaign is significant because it targets the supply chain via widely used MSP platforms, multiplying the potential impact. A single exploited MSP can lead to ransomware across many client environments, resulting in widespread operational disruption. The tactic of exploiting RMM software weaknesses is becoming more common among financially motivated groups, raising the stakes for both service providers and their customers.

Immediate Recommendations for Organisations

Organisations using N-central, either directly or via an MSP, should:

  • Ensure all N-central instances are updated to the latest secure version
  • Work with MSPs to audit privileged access and monitor for suspicious activity
  • Review ransomware incident response plans and confirm offline backups are available

Rapid action can mitigate the risk from StormEncryptor and reduce the chances of severe business disruption.

Originally reported by thehackernews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call