Skip to Content

N-able N-central exploitation results in RMM tool deployment

After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access

On August 1, 2026, N-able released an advisory disclosing active exploitation of a vulnerability affecting the N-central remote monitoring and management (RMM) platform. The vulnerability (CVE-2026-18577) is characterized as an authentication bypass that allows privileged access to the management interface of the platform in both hosted and on-premises implementations. An incomplete fix for CVE-2026-18556 published on August 1 has been reported as the underlying cause, though N-able has not directly confirmed the assertion. N-able published a hotfix to address CVE-2026-18577 on August 2 and included details about observed exploitation activity. On August 4, N-able published an additional advisory indicating that exploitation began on July 31 as a zero-day vulnerability.

Sophos Counter Threat Unit™ (CTU) researchers identified a single compromised organization in Sophos customer telemetry and have observed no evidence that compromises are widespread. The victim was compromised at approximately 08:00 UTC on August 3, and the threat actor used the compromised N-central server to access high-value endpoints such as a backup server, domain controllers, and application servers.

Attack details

During the intrusion, the threat actor created a new domain account named “veeam” and reset the passwords of several existing domain administrator accounts. Several “net user” commands were executed to enumerate existing accounts within the network. Additionally, two network reconnaissance commands were executed:

  • nltest /dclist:
  • net group “domain admins” /domain

With the remote control ability granted through exploitation of N-central, the threat actor deployed numerous RMM tools to accessible endpoints. These tools included AnyDesk (AnyDesk.exe), TacticalRMM (installed via a install_server.ps1 PowerShell script and package tacticalagent-v2.11.0-windows-amd64.exe), TeamViewer (team.msi and TeamViewer_Setup.exe), RustDesk (rustdesk.exe), SimpleHelp (service64off.exe), and HopToDesk. Cloudflare Tunnel (cloudeflared.exe) was installed on several hosts but was renamed as MicrosoftEdgeUpdate64.exe or msmp.exe to masquerade as a benign file. The threat actor used this tunnel to obtain persistent remote access to the environment.

N-able indicated that a file named svchost.exe in a user’s Documents directory (i.e., %USERPROFILE%\Documents) can reveal that the system has been compromised, but CTU researchers did not observe this filename in the victimized Sophos customer’s environment. It is possible that svchost.exe is one of the legitimate Windows filenames used by the threat actors to obscure cloudflared.exe.

The threat actor used the “tasklist” command with output piped to “findstr ms” and “findstr soph” to identify hosts running Microsoft Defender or Sophos agents, respectively. When a security product was identified, the PhantomKiller endpoint detection and response (EDR) evasion tool loaded a driver named k.sys, which was located in C:\ProgramData\AnyDesk. In one instance, PhantomKiller (named 9.exe) terminated the Sophos File Scanner process (sophosfilescanner.exe).

Recommendations, countermeasures, and indicators

CTU™ researchers advise organizations that use N-central to apply the hotfix as appropriate in their environments as soon as possible. Organizations should also search their environment for evidence that could indicate a compromise and respond accordingly.

The following Sophos countermeasure relates to this threat:

  • CXmal/KillAV-BR

The threat indicators in Table 1 can be used to detect activity related to this threat. Note that IP addresses can be reallocated. The domains and IP addresses may contain malicious content, so consider the risks before opening them in a browser.

IndicatorTypeContext
173[.]249[.]252[.]200IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
172[.]249[.]252[.]176IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
87[.]249[.]138[.]34IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577) (Note that this suspected NordVPN egress node will likely be associated with unrelated traffic)
37[.]19[.]210[.]32IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577) (Note that this suspected Mullvad VPN egress node will likely be associated with unrelated traffic)
68[.]235[.]46[.]214IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
68[.]235[.]46[.]235IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
37[.]153[.]90[.]88IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
92[.]118[.]112[.]181IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
23[.]234[.]94[.]43IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
185[.]156[.]46[.]150IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
who-ripped-one[.]direct[.]quickconnect[.]toDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
mousears[.]synology[.]meDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
wagoosh[.]direct[.]quickconnect[.]toDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
api[.]mendoratech[.]healthDomain nameTacticalRMM server used during exploitation of N-able N-central vulnerability (CVE-2026-18577)

Table 1: Indicators for this threat