Executive Summary
In August 2026, the financially motivated threat actor Storm-1175, previously associated with Medusa ransomware, began deploying a new ransomware strain named StormEncryptor. The attacks were likely initiated by exploiting an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management tool. Once inside the network, the attackers utilized tools like AnyDesk and SimpleHelp for remote management, Advanced IP Scanner for network discovery, and Mimikatz to extract credentials. StormEncryptor, written in C++, appends the ".encrypted" extension to files and drops a ransom note titled '!!!README_FIRST!!!.txt' in each directory, demanding contact within three days to prevent data leakage.
This incident underscores the evolving tactics of ransomware groups, highlighting the rapid transition from initial access to data exfiltration and encryption. The exploitation of vulnerabilities in widely used management tools like N-central emphasizes the critical need for organizations to promptly apply security patches and monitor for signs of compromise to mitigate such threats.
Why This Matters Now
The emergence of StormEncryptor ransomware, deployed by the known threat actor Storm-1175, highlights the urgent need for organizations to patch vulnerabilities like CVE-2026-18577 in N-central. The rapid progression from initial access to data encryption within days underscores the importance of proactive security measures and continuous monitoring to prevent significant operational disruptions and data breaches.
Attack Path Analysis
The attacker exploited an authentication-bypass vulnerability in the N-central RMM tool to gain initial access. They then escalated privileges by deploying tools like Mimikatz to extract credentials. Using these credentials, the attacker moved laterally across the network, identifying and accessing critical systems. They established command and control channels through remote management tools such as AnyDesk and SimpleHelp. Sensitive data was exfiltrated before deploying the StormEncryptor ransomware. Finally, the ransomware encrypted files and dropped ransom notes, demanding payment to prevent data leakage.
Kill Chain Progression
Initial Compromise
Description
Exploited an authentication-bypass vulnerability in the N-central RMM tool to gain unauthorized access.
Related CVEs
CVE-2026-18577
CVSS 8.1An authentication-bypass vulnerability in N-central remote monitoring and management (RMM) tool allows unauthenticated attackers to gain administrative access.
Affected Products:
N-able N-central – < 2026.3.1.7
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Remote Services
File and Directory Discovery
OS Credential Dumping
Data Encrypted for Impact
Exfiltration Over Web Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
StormEncryptor ransomware exploiting N-central RMM vulnerability creates critical exposure for IT service providers managing client infrastructure and remote systems.
Health Care / Life Sciences
Healthcare organizations face severe HIPAA compliance violations from StormEncryptor's rapid data exfiltration capabilities and encrypted traffic bypass vulnerabilities.
Financial Services
Banking sectors vulnerable to Storm-1175's lateral movement techniques through unencrypted east-west traffic, threatening PCI compliance and customer data protection.
Government Administration
Government agencies using N-central RMM tools face national security risks from China-based Storm-1175 actor's zero-day exploitation and credential dumping.
Sources
- New StormEncryptor ransomware used by former Medusa affiliatehttps://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/Verified
- N-central 2026.3 Hotfix 1: Mitigation for CVE-2026-18577https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/Verified
- Microsoft Threat Intelligence: Storm-1175 Activity Alerthttps://bsky.app/profile/threatintel.microsoft.com/post/3msjiybnb252nVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would likely have constrained the attacker's lateral movement and data exfiltration by enforcing strict segmentation and identity-aware policies, thereby reducing the blast radius of the incident.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, CNSF would likely limit the attacker's ability to move beyond the compromised entry point.
Control: Zero Trust Segmentation
Mitigation: Even with elevated privileges, the attacker would likely find their access restricted to specific segments, limiting further exploitation.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally would likely be constrained, reducing the risk of accessing critical systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels would likely be detected and disrupted, limiting their ability to maintain control.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be identified and blocked, reducing the risk of sensitive data being leaked.
The attacker's ability to deploy ransomware would likely be limited to the initially compromised system, reducing overall impact.
Impact at a Glance
Affected Business Functions
- Remote Monitoring and Management
- IT Support Services
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive client data managed through N-central RMM tool.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit access to critical systems.
- • Deploy East-West Traffic Security controls to monitor and control internal network traffic, detecting unauthorized movements.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and block communication with malicious external servers.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch systems, especially remote management tools, to mitigate known vulnerabilities like CVE-2026-18577.



