Microsoft has issued a warning about a China-linked hacking group exploiting a recently disclosed vulnerability in remote management software to spread ransomware through managed service providers, raising concerns over systemic security risks.
Microsoft has warned that a China-linked financially motivated hacking group is exploiting a newly disclosed flaw in widely used remote management software to push a fresh ransomware strain through managed service providers’ networks. The company said Storm-1175 began deploying malware called StormEncryptor on August 2, the same day a serious vulnerability in N-central was disclosed, raising concerns that one compromised administrative console could be used to reach many downstream clients.
According to Microsoft’s threat intelligence team, Storm-1175 has been associated with Medusa ransomware campaigns and has repeatedly targeted exposed, internet-facing systems. In April, Microsoft said the group was moving from initial access to full encryption in less than 24 hours in some cases, with victims including healthcare, professional services and financial organisations in Australia, Britain and the United States.
The new campaign centres on CVE-2026-18577, a flaw in N-central, a remote monitoring and management platform used by managed service providers to administer client endpoints. Huntress described the bug as giving attackers unauthenticated “god-mode” access, meaning a single breached server can become a launch point for attacks across an MSP’s customer base. N-able, which makes N-central, said it first spotted abuse of the weakness in a zero-day attack on July 31 and issued two emergency hotfixes after discovering that the first patch could be bypassed.
The pattern fits earlier supply-chain ransomware incidents involving remote management tools. In 2021, the REvil gang used Kaseya’s VSA platform to reach hundreds of downstream businesses, and in 2024 attackers exploited ConnectWise ScreenConnect in a similarly cascading campaign. Huntress said it had identified impacted customers of its own and found that more than half of reachable cloud-hosted N-central servers in its partner base were still unpatched, alongside 28.6% of self-hosted instances. The firm said some organisations operating in higher-risk environments may need to consider taking the tool offline, although that would also remove central visibility, patching and remote access when they may be most needed.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





