News Room
16
Share
Storm-1175 Exploits N-able Vulnerability to Deploy StormEncryptor Ransomware in Global Supply Chain Campaign
criticalThreat Intelligence

Storm-1175 Exploits N-able Vulnerability to Deploy StormEncryptor Ransomware in Global Supply Chain Campaign

Microsoft MSTIC has identified a surge in StormEncryptor ransomware deployments by Storm-1175, leveraging a critical N-able security flaw to compromise managed service providers and their downstream clients.

10 August 2026Last updated 18 August 20265 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-9981
Source:
Microsoft MSTIC
Read Time:
5 min

Executive Summary

Microsoft Threat Intelligence (MSTIC) has observed a significant escalation in activity from the threat actor designated as Storm-1175. Over the last 48 hours, this group has been actively exploiting a previously disclosed but widely unpatched vulnerability in N-able security software to deploy a new ransomware variant known as StormEncryptor. This campaign specifically targets Managed Service Providers (MSPs) to gain downstream access to hundreds of corporate networks simultaneously. The attack represents a critical evolution in supply chain extortion, moving beyond single-target compromises to automated, multi-tenant exploitation.

Threat Analysis

Storm-1175 operates under a sophisticated Ransomware-as-a-Service (RaaS) model. Unlike traditional groups that target single entities, Storm-1175 focuses on supply chain hubs. By compromising a single MSP, they can exfiltrate data from dozens of clients before triggering the encryption phase. This "force multiplier" effect has led to a surge in confirmed victims, with over 26 new breaches reported in the last 24-hour cycle alone. The group utilizes a double extortion tactic, threatening to leak sensitive intellectual property and customer databases on their "Storm Leak" portal if demands are not met. This shift toward RMM (Remote Monitoring and Management) tool exploitation highlights a growing trend where attackers prioritize access to management consoles over individual endpoints.

Technical Details

The primary entry vector involves the exploitation of an N-able security flaw (tracked as CVE-2026-9981) that allows for remote code execution on management consoles. Once access is gained, Storm-1175 deploys a Go-based encryptor (StormEncryptor) which features aggressive self-propagation capabilities across Windows domains. The malware utilizes advanced EDR-blinding techniques, including the weaponization of vulnerable drivers (BYOVD) to disable security agents before beginning the encryption process. MSTIC noted that the encryption routine is highly optimized, utilizing AES-256-GCM for file locking and RSA-4096 for key protection. Furthermore, the group has demonstrated the ability to target virtualized environments, specifically Nutanix and VMware ESXi, to maximize operational disruption.

Attribution Assessment

MSTIC attributes this activity to Storm-1175 with high confidence. The group's tactics, techniques, and procedures (TTPs) align with previous campaigns involving the "Gentlemen" ransomware group, suggesting a possible rebranding or affiliate migration. The infrastructure used for data exfiltration is hosted on decentralized storage platforms, complicating takedown efforts. The primary motivation appears strictly financial, though the scale of the supply chain compromise suggests a high level of operational maturity and resource backing typical of top-tier cybercriminal syndicates.

Implications

The exploitation of MSP tools represents a critical threat to the global digital ecosystem. As organizations increasingly rely on third-party management, the attack surface expands. The success of Storm-1175 may inspire other RaaS groups to shift focus toward RMM tools. Furthermore, the use of AI-assisted spear-phishing to harvest credentials for these consoles indicates a narrowing window for human-led defense. The potential for a single breach to cascade into hundreds of downstream outages poses a systemic risk to sectors like healthcare and manufacturing.

Recommendations

Organizations using N-able or similar RMM tools must immediately verify patch levels and audit all administrative accounts for unauthorized access. Implement strict network segmentation between MSP management environments and production workloads. MSTIC recommends deploying robust EDR solutions with tamper-protection enabled and maintaining offline, immutable backups to mitigate the impact of StormEncryptor's rapid propagation. Additionally, organizations should implement FIDO2-compliant multi-factor authentication for all remote access gateways to prevent credential-based lateral movement.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo