
Storm-1175 Exploits N-able Vulnerability to Deploy StormEncryptor Ransomware in Global Supply Chain Campaign
Microsoft MSTIC has identified a surge in StormEncryptor ransomware deployments by Storm-1175, leveraging a critical N-able security flaw to compromise managed service providers and their downstream clients.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-9981
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
Microsoft Threat Intelligence (MSTIC) has observed a significant escalation in activity from the threat actor designated as Storm-1175. Over the last 48 hours, this group has been actively exploiting a previously disclosed but widely unpatched vulnerability in N-able security software to deploy a new ransomware variant known as StormEncryptor. This campaign specifically targets Managed Service Providers (MSPs) to gain downstream access to hundreds of corporate networks simultaneously. The attack represents a critical evolution in supply chain extortion, moving beyond single-target compromises to automated, multi-tenant exploitation.
Threat Analysis
Storm-1175 operates under a sophisticated Ransomware-as-a-Service (RaaS) model. Unlike traditional groups that target single entities, Storm-1175 focuses on supply chain hubs. By compromising a single MSP, they can exfiltrate data from dozens of clients before triggering the encryption phase. This "force multiplier" effect has led to a surge in confirmed victims, with over 26 new breaches reported in the last 24-hour cycle alone. The group utilizes a double extortion tactic, threatening to leak sensitive intellectual property and customer databases on their "Storm Leak" portal if demands are not met. This shift toward RMM (Remote Monitoring and Management) tool exploitation highlights a growing trend where attackers prioritize access to management consoles over individual endpoints.
Technical Details
The primary entry vector involves the exploitation of an N-able security flaw (tracked as CVE-2026-9981) that allows for remote code execution on management consoles. Once access is gained, Storm-1175 deploys a Go-based encryptor (StormEncryptor) which features aggressive self-propagation capabilities across Windows domains. The malware utilizes advanced EDR-blinding techniques, including the weaponization of vulnerable drivers (BYOVD) to disable security agents before beginning the encryption process. MSTIC noted that the encryption routine is highly optimized, utilizing AES-256-GCM for file locking and RSA-4096 for key protection. Furthermore, the group has demonstrated the ability to target virtualized environments, specifically Nutanix and VMware ESXi, to maximize operational disruption.
Attribution Assessment
MSTIC attributes this activity to Storm-1175 with high confidence. The group's tactics, techniques, and procedures (TTPs) align with previous campaigns involving the "Gentlemen" ransomware group, suggesting a possible rebranding or affiliate migration. The infrastructure used for data exfiltration is hosted on decentralized storage platforms, complicating takedown efforts. The primary motivation appears strictly financial, though the scale of the supply chain compromise suggests a high level of operational maturity and resource backing typical of top-tier cybercriminal syndicates.
Implications
The exploitation of MSP tools represents a critical threat to the global digital ecosystem. As organizations increasingly rely on third-party management, the attack surface expands. The success of Storm-1175 may inspire other RaaS groups to shift focus toward RMM tools. Furthermore, the use of AI-assisted spear-phishing to harvest credentials for these consoles indicates a narrowing window for human-led defense. The potential for a single breach to cascade into hundreds of downstream outages poses a systemic risk to sectors like healthcare and manufacturing.
Recommendations
Organizations using N-able or similar RMM tools must immediately verify patch levels and audit all administrative accounts for unauthorized access. Implement strict network segmentation between MSP management environments and production workloads. MSTIC recommends deploying robust EDR solutions with tamper-protection enabled and maintaining offline, immutable backups to mitigate the impact of StormEncryptor's rapid propagation. Additionally, organizations should implement FIDO2-compliant multi-factor authentication for all remote access gateways to prevent credential-based lateral movement.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Ransomware Surge: Over 1,000 Organizations Compromised in August 2026 Amidst Escalating Gang Conflicts

Global Ransomware Surge: September 2026 Intelligence Update on ShinyHunters and MedusaLocker Activity

