A group of hackers with ties to China, known as Storm-1175, has been leveraging a critical vulnerability in widely-used cybersecurity software to launch a ransomware attack. This flaw, found in N-central, a remote monitoring and management console from N-able, is being used as part of a supply-chain attack to deploy a new ransomware strain called StormEncryptor. Microsoft Threat Intelligence raised the alarm this past weekend, noting that these attackers can gain full administrative access to N-central servers without any credentials, effectively turning a compromised server into a launchpad for further attacks.

The situation is particularly concerning because N-central is utilized by thousands of managed service providers to manage client endpoints. This means that a breach at a single provider could potentially affect numerous downstream organizations. The vulnerability was disclosed on August 2, coinciding with the start of the StormEncryptor deployments, although Microsoft has not confirmed the exact access vector.

This attack is reminiscent of previous incidents where vulnerabilities in remote monitoring tools were exploited to launch widespread ransomware campaigns. For instance, in 2021, the REvil ransomware gang used a similar flaw in a Kaseya tool to affect 1,500 businesses, and in 2024, ConnectWise's ScreenConnect product was compromised in another supply-chain attack.

N-able, the company behind N-central, has been actively working to address the issue. An initial patch proved inadequate, leading to a series of emergency hotfixes. Despite these efforts, many N-central servers remain unpatched, leaving them vulnerable to attack. Huntress, a cybersecurity firm, reported that over half of the reachable N-central cloud servers in its partner base were still exposed as of the latest updates.

This ongoing situation highlights the critical need for organizations to promptly apply security patches and continuously monitor their systems for vulnerabilities. The rapid pace at which Storm-1175 has moved from initial access to full encryption underscores the importance of swift and decisive action.