China-Linked Hackers Are Using IT Management Software as a Ransomware Weapon — Small Businesses Take Note
If your computers are managed remotely by an IT provider, there's a question you should be asking them today: Have you applied the latest patch to N-central?
It's not a hypothetical. Right now, a China-linked hacker group is actively exploiting a critical vulnerability in one of the most widely used IT management tools in the industry — and your business could be caught in the crossfire without ever knowing it.
What's Happening
The Hacker News reports that Microsoft's Threat Intelligence Team has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. Written in C++, StormEncryptor appends the .encrypted extension to every file it locks and drops a ransom note named !!!README_FIRST!!!.txt in every scanned directory.
This marks a significant shift for the group. Storm-1175 was previously known for deploying Medusa ransomware against healthcare, professional services, and finance organizations in Australia, Britain, and the United States. The switch to a custom-built strain suggests the group is evolving — and investing in tools designed to evade detection.
The likely entry point? A critical flaw called CVE-2026-18577 in N-able N-central, a remote monitoring and management (RMM) platform used by thousands of managed service providers (MSPs) to administer client systems. According to The Record, Microsoft noted that StormEncryptor deployments began on August 2 — the same day the vulnerability was publicly disclosed.
Why N-central Makes This Especially Dangerous
Here's what makes this attack so alarming for small businesses: you may not even use N-central directly, but your IT provider might.
MSPs use N-central to remotely manage, monitor, and patch the computers of all their clients from one central console. As The Record explains, the vulnerability gives attackers "unauthenticated, 'god-mode' access" — meaning someone with no credentials whatsoever can gain full administrative control of an N-central server. Once they're in, every endpoint that server manages becomes a potential ransomware target.
That single point of compromise is what makes supply-chain attacks so devastating. In 2021, a similar attack on Kaseya — another RMM tool — allowed the REvil ransomware gang to initially compromise 60 direct customers before hitting approximately 1,500 downstream businesses. The 2024 ConnectWise ScreenConnect breach followed the same pattern, and Storm-1175 was among the threat actors targeting it at the time.
CVE-2026-18577 is assessed to be a patch bypass for an earlier vulnerability, CVE-2026-18556 — both of which allow authentication bypass and account takeover. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged both flaws as actively exploited in the wild.
The Attack Happens Fast
One of the most chilling details in Microsoft's disclosure is the speed of these attacks. The Record reports that Microsoft has seen Storm-1175 move from initial access to full encryption in under 24 hours. In other cases, the group moves from access to data exfiltration and ransomware deployment within just a few days.
According to Help Net Security, once the attackers exploit CVE-2026-18577, they use N-central's legitimate Take Control feature to connect to managed endpoints, then register a new service for a Cloudflare tunnel to maintain persistence. Sophos researchers found that the attackers also created a new domain account named "veeam," reset passwords on existing administrator accounts, installed additional remote-access tools, and disabled security software from both Microsoft and Sophos using an EDR-evasion tool.
The Microsoft Threat Intelligence Team further noted that Storm-1175's post-compromise toolkit includes abuse of AnyDesk or SimpleHelp for remote access, Advanced IP Scanner for network discovery, and Mimikatz for dumping credentials from LSASS memory.
The Patch Situation Is Complicated
Making matters worse: fixing this vulnerability hasn't been straightforward. Help Net Security reports that N-able first detected unusual activity on July 31, 2026, when its Adlumin MDR solution flagged exploitation of a zero-day. An initial patch was shipped on August 2 — but attackers quickly found a way around it, forcing N-able to release an emergency Hotfix 2 on August 6 with additional hardening measures.
N-able has been explicit: "Hotfix 2 is required, even if you already applied the earlier hotfix."
Even with patches available, Huntress researchers found that more than half of reachable N-central cloud servers across their partner base were still unpatched, with 28.6% of self-hosted instances remaining exposed.
What Small Businesses Should Do Right Now
You don't need to be a cybersecurity expert to take action here. The most important thing is to ask your IT provider the right questions:
Do you use N-able N-central to manage my systems? Many small business owners simply don't know what tools their provider uses behind the scenes. Now is the time to find out.
Have you applied N-central version 2026.3.1.10 (Hotfix 2)? This is the specific version N-able says is required for full protection. Hotfix 1 is not sufficient.
What is your patching timeline when a critical vulnerability is disclosed? Storm-1175 has a documented history of exploiting vulnerabilities within days — sometimes before patches are even publicly available. If your provider's answer is "within a few weeks," that's a problem.
What indicators of compromise are you monitoring for? N-able has published a list of IP addresses associated with the attacks, and Sophos has expanded that list with additional command-and-control server details.
Are managed agents on my devices also updated? Help Net Security notes that while not strictly required, upgrading agents on managed devices is recommended to fully protect endpoints from CVE-2026-18577.
The Bigger Takeaway for Local Businesses
This attack illustrates a risk that many Yuba City small businesses don't think about: your security is only as strong as the tools your IT provider uses — and how quickly they patch them. When an MSP's management platform is compromised, every business on their client list becomes a target. You don't have to do anything wrong to get hit.
That's why asking about your provider's patching practices isn't paranoid — it's smart business. Storm-1175's history of targeting healthcare, professional services, and finance sectors means this isn't a threat aimed only at large enterprises. Small and mid-sized businesses are frequently in the crosshairs precisely because they tend to have less visibility into these supply-chain risks.
If you're not sure whether your current IT setup adequately protects you from threats like this, our business IT services include a review of your current environment and can help you understand exactly what software is touching your systems and whether it's up to date.
The conversation starts with one question: "Has your provider applied the latest patch?" Ask it today.