China-linked hackers exploit software flaw in ransomware supply-chain attack

Microsoft Threat Intelligence warned that Storm-1175, a financially motivated group linked to China, is exploiting a critical vulnerability in N-central, a remote monitoring tool used by managed service providers, to deploy custom ransomware called StormEncryptor across victim networks. The group began attacks on August 2, the same day the flaw in N-central was disclosed, gaining what Huntress described as "unauthenticated, 'god-mode' access" to servers that control thousands of downstream business endpoints.
A single compromised N-central server can cascade into dozens of ransomware incidents across an MSP's entire client base. Storm-1175 previously used Medusa ransomware to target healthcare, professional services and finance organisations in Australia, Britain and the United States, and has moved from initial access to full encryption in under 24 hours. N-able, which makes N-central, said it contacted a "limited number" of affected customers. Huntress found more than half of reachable N-central cloud servers across its partner base remained unpatched even after emergency fixes were issued on August 2 and August 6, The Record reports.