China-Linked Hacking Group Exploits N-central Flaw in Fresh Ransomware Wave
A financially motivated hacking group linked to China has started exploiting a severe security flaw in N-central, a widely used remote management tool. This vulnerability allows unauthenticated attackers to gain full administrative control over an affected server.
The group, known as Storm-1175, began deploying a new ransomware variant called StormEncryptor on August 2, the same day the underlying vulnerability was publicly disclosed. Microsoft's threat intelligence team detected this activity and has been tracking the group's operations since April.
N-central is used by thousands of managed service providers (MSPs) to administer client computers and servers. A single compromised MSP server can serve as a gateway into dozens or hundreds of downstream businesses, making supply-chain intrusions especially attractive to ransomware operators.