CyberSecurity SEE

China-Linked Hackers Exploit N-able Vulnerability in Ransomware Attacks

China-Linked Hackers Exploit N-able Vulnerability in Ransomware Attacks

Microsoft Warns of Ransomware Attacks by China-Linked Storm-1175 Group

In a recent security alert, Microsoft has revealed that a financially motivated hacking group, identified as Storm-1175 and linked to China, has been actively deploying a new strain of ransomware since August 2, 2026. This resurgence appears to have occurred in the wake of exploiting a critical vulnerability in N-able’s remote monitoring and management software known as N-central. According to Microsoft’s Threat Intelligence team, this newly implemented C++-based ransomware, dubbed StormEncryptor, signals a tactic shift from the group’s previous software known as Medusa, which had brought them into the cybersecurity spotlight earlier this year.

The tactics adopted by Storm-1175 include the use of various remote monitoring and management tools such as AnyDesk and SimpleHelp, as well as the Advanced IP Scanner for system discovery. The illicit practices further extend to utilizing Microsoft’s Local Security Authority Subsystem Service for credential dumping by employing widely used credential theft tools like Mimikatz. The group is remarkably efficient, often transitioning from initial access to data exfiltration and subsequent ransomware deployment within mere days, or, in some cases, even within 24 hours.

The vulnerability exploited by the group is tracked as CVE-2026-18577, characterized as an authentication bypass issue within N-central. Alarmingly, Microsoft indicated that the exploitation of this flaw occurred on the very same day it was publicly disclosed, highlighting the rapid pace at which these threat actors operate. N-central is a widely adopted tool among managed service providers (MSPs) for monitoring, patching, and obtaining remote access to servers and endpoints across multiple customer platforms, which means that the ramifications of this exploitation could be considerable, affecting hundreds, if not thousands of downstream systems dispersed throughout regions like Asia-Pacific, Europe, and the Americas.

In light of these alarming developments, N-able struggled to address the threat properly. The company originally detected the active exploitation of the zero-day vulnerability on July 31, 2026. However, its initial assessment downplayed the potential impact, mistakenly suggesting that only on-premises servers were at risk. The company’s first patch proved inadequate, failing to prevent further attacks.

On August 2, following the vulnerability advisory, discussions surrounding CVE-2026-18577 intensified. This flaw allows a remote and unauthenticated attacker to bypass authentication protocols and gain administrative control over all versions of vulnerable RMM servers, whether they are hosted on-premises or in the cloud. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) acknowledged the problem shortly thereafter by adding it to their catalog of known exploited vulnerabilities.

According to experts from security intelligence firm Rapid7, the potential for remote attackers to gain administrative access to susceptible N-central servers raises red flags, as they can exploit the built-in Take Control feature to pivot into managed endpoints effectively. This enables them to establish Cloudflare-based tunnels for persistent access.

Despite N-able’s attempt to mitigate the situation by rolling out two emergency hotfixes, Storm-1175’s speed rendered many deployments vulnerable. Victims experienced file encryption and received ransom notes, which threatened the public release of stolen data if demands were not met promptly.

The criminal group has diversified its targets, with a growing list of victim companies across various sectors, including e-commerce, fintech, healthcare, and home security, appearing on Storm-1175’s ransom site. This mirrors strategies previously observed during the group’s operations under the Medusa pseudonym, where they capitalized on legitimate RMM tools to maintain a foothold within compromised networks.

These tools, initially designed for IT teams’ efficiency, can also facilitate attackers to create new user accounts or enable alternative command-and-control (C2) methods. Moreover, the use of Mimikatz allows for credential dumping from the LSASS process memory, which often contains not only current user credentials but also those of domain administrators, significantly increasing the attackers’ ability to manipulate entire networks rather than just individual devices.

Once domain credentials are obtained, attackers can traverse the network through legitimate mechanisms such as PsExec or Windows Management Instrumentation, or by employing techniques like pass-the-hash, allowing them to authenticate without needing access to users’ plaintext passwords. With elevated privileges, Storm-1175 can further exploit PsExec to infiltrate domain controllers, stealing sensitive Active Directory data, including user account information and password hashes that can be cracked offline.

This evolving scenario highlights the critical need for organizations to prioritize cybersecurity measures. Microsoft has urged affected organizations to remain vigilant, continuously monitor for Storm-1175 activity, and apply security patches without delay to fortify their defenses against these imminent threats.

Source link

Exit mobile version