Storm-1175 possibly behind recent N-able N-central zero-day attacks

 

Storm-1175 possibly behind recent N-able N-central zero-day attacks

Microsoft Threat Intelligence has observed a financially motivated cybercriminal group, tracked as Storm-1175, deploying a new ransomware strain called StormEncryptor on August 2, 2026. Previously, the threat actor leveraged the Medusa ransomware in its attacks.

StormEncryptor is written in C++ and adds the .encrypted extension to encrypted files. It also places a !!!README_FIRST!!!.txt ransom note in scanned directories.

Microsoft has not confirmed which vulnerability was used in the latest campaign, but Storm-1175 is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed at the beginning of this month.

In the observed attack, Storm-1175 deployed remote monitoring and management tools, including AnyDesk and SimpleHelp, and used Advanced IP Scanner for discovery, as well as LSASS dumping using Mimikatz.

Storm-1175 is known for quickly exploiting recently disclosed vulnerabilities, often before organizations have time to patch them. Since 2023, Microsoft has linked the group to exploitation of more than 16 vulnerabilities, including CVE-2023-21529 in Microsoft Exchange; CVE-2023-27351 and CVE-2023-27350 in PaperCut; CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure and Policy Secure; CVE-2024-1709 and CVE-2024-1708 in ConnectWise ScreenConnect; CVE-2024-27198 and CVE-2024-27199 in JetBrains TeamCity; CVE-2024-57726, CVE-2024-57727 and CVE-2024-57728in SimpleHelp;CVE-2025-31161 in CrushFTP; CVE-2025-10035 in GoAnywhere MFT; CVE-2025-52691 and CVE-2026-23760 in SmarterMail; and CVE-2026-1731 in BeyondTrust.

The group has sometimes weaponized vulnerabilities within days of disclosure. For example, CVE-2025-31324 affecting SAP NetWeaver was disclosed on April 24, 2025, and Storm-1175 exploitation was observed the following day.

Storm-1175 has also chained vulnerabilities to gain further access. In July 2023, it exploited CVE-2022-41080 against Microsoft Exchange to expose Exchange PowerShell through Outlook Web Access, followed by CVE-2022-41082 to achieve remote code execution.

The group has also targeted Linux systems, including vulnerable Oracle WebLogic servers in late 2024. Microsoft could not determine the exact vulnerability used in the attacks.

Storm-1175 has additionally exploited at least three zero-day vulnerabilities, including CVE-2026-23760 in SmarterMail and CVE-2025-10035 in GoAnywhere MFT, both of which were exploited before public disclosure. The activity shows that Storm-1175 can obtain or develop exploits quickly, although the group mainly uses N-day vulnerabilities.

Back to the list