China-Linked Hackers: Cybersecurity Tool's Dark Side Exposed (2026)

China-linked hackers are exploiting a critical vulnerability in a popular cybersecurity tool, turning it into a ransomware launchpad, Microsoft warns. This supply-chain attack could have devastating consequences for countless organizations.

The Storm-1175 group, believed to be linked to China, is deploying a new ransomware strain called StormEncryptor. This group has previously used the Medusa ransomware to extort healthcare, professional services, and finance organizations in Australia, Britain, and the United States. Their high-velocity campaigns exploit both disclosed vulnerabilities and zero-day exploits, sometimes a full week before public disclosure.

In this latest campaign, Microsoft suspects the group is exploiting CVE-2026-18577, a vulnerability in N-central, a remote monitoring and management console. This vulnerability gives attackers unauthenticated, 'god-mode' access, allowing them to gain full administrative control of an N-central server with no credentials. Because MSPs use N-central to manage client endpoints, a single compromised server can become a gateway to every endpoint it controls.

This is not the first time such an attack has occurred. In 2021, a supply-chain attack on Kaseya's RMM tool allowed the REvil ransomware gang to compromise 60 of Kaseya's direct customers, leading to numerous downstream ransomware incidents. Similarly, a 2024 attack on ConnectWise's ScreenConnect product impacted numerous downstream entities.

The vulnerability in N-central was first detected in a zero-day attack on July 31, and N-able, the software company behind N-central, issued emergency hotfixes on August 2 and 6. However, Huntress found that over half of reachable N-central cloud servers remained unpatched, leaving them exposed. Turning N-central offline may be necessary for some organizations, but it also means losing central visibility and remote access when they may be needed most.

This incident highlights the ongoing threat of supply-chain attacks and the importance of patching and securing critical software. As threat actors continue to exploit vulnerabilities, organizations must remain vigilant and proactive in their cybersecurity efforts.

China-Linked Hackers: Cybersecurity Tool's Dark Side Exposed (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Kieth Sipes

Last Updated:

Views: 5759

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Kieth Sipes

Birthday: 2001-04-14

Address: Suite 492 62479 Champlin Loop, South Catrice, MS 57271

Phone: +9663362133320

Job: District Sales Analyst

Hobby: Digital arts, Dance, Ghost hunting, Worldbuilding, Kayaking, Table tennis, 3D printing

Introduction: My name is Kieth Sipes, I am a zany, rich, courageous, powerful, faithful, jolly, excited person who loves writing and wants to share my knowledge and understanding with you.