Breaking Geopolitics News & AnalysisWednesday, August 12, 2026
DiplomacyNorth America

Hackers Linked to China Could Be Exploiting Remote Software

The National Interest
August 12, 2026 at 4:00 PM
5 views
Hackers Linked to China Could Be Exploiting Remote Software

The “Storm-1175” hacking group has developed a new type of malware, using multiple zero-day exploits to quickly take control of computer systems and hold them for ransom. The post Hackers Linked to China Could Be Exploiting Remote Software appeared first on The National Interest.

The “Storm-1175” hacking group has developed a new type of malware, using multiple zero-day exploits to quickly take control of computer systems and hold them for ransom.

A hacking group that is believed to have links to China began to deploy a new ransomware strain earlier this month. According to Microsoft Threat Intelligence, the group known as “Storm-1175” reemerged after several months of inactivity, and moved away from its “Medusa” ransomware.

The newly released “StormEncryptor” ransomware is more worrisome, Microsoft researchers noted in a post on social media, stating it is written in C++ and that it can target remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and Windows Local Security Authority Subsystem Service. The tool exploits an authentication bypass vulnerability, which is tracked as CVE-2026-18577, in the networking monitoring provider N-able’s N-central platform.

“Storm-1175 is known to operate high-velocity ransomware campaigns that weaponize N-days, taking advantage of the window between vulnerability disclosure and patch adoption,” Microsoft Threat Intelligence warned.

N-able has already issued two emergency hotfixes to address the vulnerability, but not before Storm-1175 was able to exploit unpatched deployments within several companies, holding data for ransom.

Impacted industries include e-commerce, fintech, healthcare, and home security, GovInfoSecurity.com reported.

Why Storm-1175 Is So Dangerous

As with many international hacking groups, few details are actually known about Storm-1175, apart from its alleged ties to China. The group has become somewhat infamous for its exceptionally high operational tempo, which according to Microsoft researchers, has frequently moved from initial perimeter compromise to full data exfiltration and ransomware deployment in under 24 hours.

The group’s modus operandi typically involves the weaponization of newly disclosed N-day and zero-day vulnerabilities in Internet-facing perimeter services and enterprise software.

“The biggest takeaway isn’t just another critical vulnerability—it’s that attackers are increasingly targeting the tools organizations trust most,” wrote Phillip Wylie, chief security evangelist and senior consultant for cybersecurity provider Suzu Labs, in an email to The National Interest.

“RMM platforms, identity systems, and security products provide privileged access by design, making them ideal force multipliers for threat actors,” Wylie warned. “Organizations should treat these platforms as crown-jewel assets, prioritize rapid patching, closely monitor privileged activity, and assume that even trusted management infrastructure can become an attack vector.”

Cyberattacks Are Part of China’s Great Power Game

The other side of this story is how a financially motivated cybercriminal threat actor is also part of China’s ongoing campaign against Western interests. Storm-1175 isn’t just a group of technically skilled thieves; it is likely a well-funded and well-organized unit that is exploiting weaknesses within US and international firms.

Cyber exploitation tools such as StormEncryptor could be as ominous a threat to US interests as Beijing’s new aircraft carriers, or its J-20 Mighty Dragon stealth fighter.

“This particular attack fits into China’s broader cyber great power initiative that they’ve been working on for well over a decade, building the capability to exploit and gain access to as many systems as possible,” explained John Strand, owner of Black Hills Information Security.

Strand told The National Interest via an email that this particular attack was likely triggered by the vulnerability being discovered.

More worrisome is the fact that China may have already been exploiting it for some period of time before the vendor publicly disclosed it on July 31.

 “This gets into a larger question that I think we need to ask whenever we see nation-state attacks suddenly transition into ransomware campaigns. What were they doing before,” Strand pondered.

For China, Ransomware Attacks Aren’t About Money

For traditional cybercriminals, the goal of ransomware is to get paid. In that regard, those conducting such campaigns are little more than digital pirates preying on desperate companies or entities that will see that paying a ransom is less costly and less burdensome than attempting a software solution.

Some nations, notably North Korea and Iran, employ ransomware and cyber theft to bypass severe global economic sanctions and generate illicit cash for the ruling regime. Each utilizes state-backed hacking units that treat cyber operations as a vital strategic tool for survival and regime enrichment. As an added bonus, these attacks also allow the rogue states to carry out asymmetric attacks on the West in ways that are difficult to retaliate against.

However, for the great powers, ransomware takes a different form.

“With a nation state like China, Russia, or even the United States, the primary goal generally isn’t ransomware. The goal is access. They want to dwell inside environments and maintain that access for as long as they possibly can,” Strand wrote. “The way this particular attack has been linked to China leads me to believe the vulnerability may have been used for that type of access and persistence for some period of time. But once the vulnerability became public and a patch was available, its usefulness for longer-term nation-state operations dropped significantly.
At that point, it would serve to transfer the capability over to another ransomware operation and extract whatever remaining value can be gained from the vulnerable systems that are still out there.”

About the Author: Peter Suciu

Peter Suciu has contributed to dozens of newspapers, magazines and websites over a 30-year career in journalism. He regularly writes about military hardware, firearms history, cybersecurity, politics, and international affairs. Peter is also a contributing writer for Forbes and Clearance Jobs. He is based in Michigan. You can follow him on Twitter: @PeterSuciu. You can email the author: Editor@nationalinterest.org.

The post Hackers Linked to China Could Be Exploiting Remote Software appeared first on The National Interest.