Dark web leak site monitoring via ransomware.live confirms the N0N ransomware group posted 11 new victims between 2026-09-18 and 2026-09-20 — a compressed burst of disclosures that indicates either a coordinated detonation wave or a backlog dump following a negotiation deadline. The victim set spans 8 countries (US, VE, SE, AR, TR, LU, BR, VN) and 8 sectors, with a pronounced concentration in Financial Services (3 victims), Education (2), and high-value single strikes against Retail/E-Commerce (Fanatics), Telecom (Inter — Venezuela's largest ISP), Government (Argentine Ministry of Education), and Pharma (AstraZeneca Türkiye).
Of particular concern: at least two victims appear to be supply-chain pivots — Transcom WorldWide (a BPO provider operating PayPal support operations) and an AWS-hosted education platform — consistent with N0N's established pattern of targeting service providers to cascade impact into downstream clients. Security teams at MSPs, BPOs, cloud-hosted SaaS providers, and any organization running exposed VMware vCenter, Cisco FMC, Check Point gateways, or ConnectWise ScreenConnect should treat this bulletin as action-required.
Threat Actor Profile — N0N
| Attribute | Assessment |
|---|---|
| Aliases | N0N, NON, N0N Ransom; no confirmed rebrand lineage, though TTP overlap suggests operator migration from defunct mid-tier RaaS programs |
| Operating Model | Closed group / private RaaS hybrid — small trusted affiliate circle rather than open recruitment; victim cadence and consistent negotiation style indicate centralized operation of the leak site and payment infrastructure |
| Ransom Demands | Typically $500K–$5M USD, scaled to victim revenue; outliers against major brands (Fanatics-tier) assessed in the $8M–$15M range. Demands issued in Monero or BTC via Tor negotiation portal |
| Initial Access | Perimeter appliance exploitation (VPN/firewall zero-days and n-days), exposed RDP brute force, and phishing with macro-laden documents or OneNote/LNK loaders. Increasing use of compromised BPO/service-provider credentials as a pivot |
| Extortion Model | Double extortion — data exfiltrated and staged on leak site before encryption; partial data leaks used as escalation pressure at 72-hour and 7-day marks |
| Dwell Time | Average 5–11 days from initial access to detonation; larger enterprise intrusions observed up to 21 days with extensive pre-encryption reconnaissance |
| Toolset | Cobalt Strike, PsExec/Impacket, WMI, Rclone/MEGA for exfil, AnyDesk/ScreenConnect for persistence, custom .NET-based encryptor with intermittent encryption for speed |
Analyst Note: N0N's leak site posting pattern — single-day multi-victim drops followed by quiet periods — is characteristic of a crew that batches intrusions and times disclosures to maximize negotiation leverage, not a spray-and-pray RaaS.
Current Campaign Analysis
Sector Targeting (Last 11 Postings)
- Financial Services (3/11 — 27%): Argentem Creek Partners (investment), STOKR (digital securities), Transcom WorldWide (PayPal support BPO). N0N is clearly prioritizing organizations holding transactional, client PII, and regulated financial data — maximum regulatory and reputational pressure.
- Education (2/11): United Federation of Teachers (US), BeLi Teacher/FSC centers (VN, AWS-hosted). Education remains a soft-target staple: large PII volumes, weak segmentation, under-resourced security teams.
- Government & Defense (1/11): Argentine Ministry of Education — signals willingness to hit sovereign targets in Latin America, where ransom payment decisions face fewer sanctions complications than US federal entities.
- Technology / Telecom (1/11): Inter, Venezuela's largest ISP — a critical infrastructure strike with potential for upstream visibility into subscriber traffic and downstream business customers.
- Healthcare (1/11): AstraZeneca Türkiye — regional subsidiary targeting rather than corporate HQ, a classic N0N move to hit weaker regional security postures of global brands.
- Retail & E-Commerce (1/11): Fanatics — the campaign's marquee victim; global sports commerce with massive customer PII and payment-adjacent data.
- Professional Services (1/11) & Other (1/11): Brazilian legal services firm and a Vietnamese betting operator — the latter suggests N0N has no ethical targeting floor and will hit gray-market operators who cannot report to law enforcement.
Geographic Concentration
- US (3), Vietnam (2) lead; single victims across VE, SE, AR, TR, LU, BR. This is a globally opportunistic campaign, not regionally focused — consistent with perimeter-vulnerability scanning at internet scale rather than targeted spear-phishing.
Victim Profile
- Size range: Mid-market (50–500 employees) through large enterprise (Fanatics, AstraZeneca regional, national ISP, federal ministry).
- Revenue estimates: ~$10M–$50M (Konnatus, STOKR, BeLi) up to $1B+ (Fanatics, Inter, AstraZeneca Türkiye operations). N0N is running a barbell strategy: quick mid-market payouts plus a small number of high-leverage brand-name extortions.
Posting Frequency & Escalation
- 10 of 11 victims posted on 2026-09-18 — a single-day mass disclosure, followed by the Fanatics post on 2026-09-20. This cadence indicates a synchronized encryption wave executed roughly 5–11 days prior (early-to-mid September intrusion window). Expect a second wave of postings within 14–21 days as currently-dormant intrusions mature.
CVE Correlation — Likely Initial Access Vectors
The victim geography and sector spread align strongly with internet-facing appliance exploitation rather than per-victim phishing. Priority exposure checks:
| CVE | Product | KEV Added | Campaign Relevance |
|---|---|---|---|
| CVE-2026-59310 | Broadcom VMware vCenter (path traversal) | 2026-08-18 | Highest priority — vCenter compromise yields direct ESXi/datastore access, enabling mass VM encryption, N0N's preferred detonation model |
| CVE-2026-50751 | Check Point Security Gateway (improper auth, IKEv1) | 2026-06-08 | VPN gateway takeover → internal network access with valid-looking tunnels |
| CVE-2026-20316 | Cisco Secure FMC (hard-coded password) | 2026-07-29 | Management-plane compromise → firewall policy manipulation, traffic interception |
| CVE-2024-1708 | ConnectWise ScreenConnect (path traversal → RCE) | 2026-04-28 | MSP/BPO pivot vector — directly relevant to the Transcom WorldWide intrusion pattern |
| CVE-2026-48027 | Nx Console (embedded malicious code) | 2026-05-27 | Supply-chain/dev-workstation foothold — candidate vector for the AWS-hosted education victim |
Assessment (moderate confidence): The Transcom WorldWide/PayPal-support intrusion is consistent with ScreenConnect or BPO credential compromise; the Fanatics and Inter intrusions are consistent with vCenter/edge-appliance exploitation given their VMware-heavy infrastructure footprints.
Detection Engineering
The following detections target N0N's observed playbook: (1) VPN/edge-appliance exploitation followed by anomalous authentication, (2) phishing-driven macro/OneNote execution spawning script interpreters, and (3) pre-encryption staging — PsExec/WMI lateral movement, Rclone exfiltration, and shadow copy deletion.
---
title: N0N Ransomware - Suspicious Process Spawned by VPN or Edge Appliance Service
description: Detects child processes spawned from VPN/firewall management services (Check Point, Cisco FMC, Fortinet) consistent with post-exploitation of CVE-2026-50751 / CVE-2026-20316 by N0N operators
status: experimental
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
service: sysmon
detection:
selection_parent:
ParentImage|endswith:
- '\vpnd.exe'
- '\cpm.exe'
- '\fw1.exe'
- '\sfmgr.exe'
- '\httpd.exe'
- '\tomcat.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\rundll32.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Legitimate appliance management scripts (rare on Windows hosts)
level: high
tags:
- attack.initial_access
- attack.t1190
- attack.t1059
date: 2026/09/22
---
title: N0N Ransomware - Phishing Loader Execution via Office or OneNote Spawning Script Interpreters
description: Detects Office or OneNote processes spawning script/PowerShell children, consistent with N0N phishing macros and .one loader attachments observed in 2026 intrusions
status: experimental
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
service: sysmon
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\onenote.exe'
- '\outlook.exe'
- '\msedge.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\cmd.exe'
- '\rundll32.exe'
filter_child_cmd:
CommandLine|contains:
- ' -enc '
- ' -e '
- 'downloadstring'
- 'invoke-expression'
- 'iex'
- 'hidden'
- 'bypass'
condition: selection_parent and selection_child and filter_child_cmd
falsepositives:
- Rare; legitimate Office automation rarely uses encoded or bypass flags
level: high
tags:
- attack.initial_access
- attack.t1566.001
- attack.t1204.002
- attack.t1059.001
date: 2026/09/22
---
title: N0N Ransomware - Pre-Encryption Staging and Exfiltration Indicators
description: Detects N0N pre-detonation behavior - shadow copy deletion, PsExec service creation, Rclone execution, and mass file rename activity within a short window
status: experimental
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
service: sysmon
detection:
selection_vss:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
- '\wbadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'recoveryenabled no'
- 'delete catalog'
selection_exfil:
Image|endswith:
- '\rclone.exe'
- '\megacmd.exe'
- '\7z.exe'
- '\winrar.exe'
- '\rar.exe'
CommandLine|contains:
- 'copy'
- 'sync'
- 'move'
- ' a '
- ' -p'
selection_psexec:
Image|endswith:
- '\psexec.exe'
- '\psexesvc.exe'
- '\paexec.exe'
CommandLine|contains:
- ' -s '
- ' -d '
- 'accepteula'
condition: 1 of selection_*
falsepositives:
- Admin backup maintenance (vssadmin), legitimate archiving (7z) - tune per environment
level: critical
tags:
- attack.impact
- attack.t1490
- attack.t1569.002
- attack.t1560.001
- attack.exfiltration
- attack.t1567.002
date: 2026/09/22
// N0N Pre-Ransomware Staging Hunt - Microsoft Sentinel
// Hunts lateral movement + exfil staging chains within N0N's 5-11 day dwell window
let Lookback = 14d;
let SuspiciousTools = dynamic(["psexec.exe","psexesvc.exe","paexec.exe","rclone.exe","megacmd.exe","anydesk.exe","screenconnect.exe","nltest.exe","adfind.exe","sharp-hound.exe","bloodhound.exe"]);
let ReconHosts =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName has_any ("nltest.exe","adfind.exe","bloodhound.exe","sharp-hound.exe")
or ProcessCommandLine has_any ("/dcList","dclist:","domain_trusts","gpp_password")
| summarize ReconTime=min(TimeGenerated) by DeviceName, AccountName;
let ToolUse =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName in~ (SuspiciousTools)
or ProcessCommandLine has_any ("rclone copy","rclone sync","mega-put","accepteula")
| project ToolTime=TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName;
let VssTamper =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where ProcessCommandLine has_any ("delete shadows","shadowcopy delete","recoveryenabled no","delete catalog","resize shadowstorage")
| project VssTime=TimeGenerated, DeviceName, VssCommand=ProcessCommandLine, VssAccount=AccountName;
let MassRename =
DeviceFileEvents
| where TimeGenerated > ago(2d)
| where ActionType == "FileRenamed"
| summarize RenameCount=count(), DistinctExtensions=dcount(strcat(split(FileName,".")[-1])) by DeviceName, bin(TimeGenerated, 10m)
| where RenameCount > 200
| project RenameWindow=TimeGenerated, DeviceName, RenameCount;
ToolUse
| join kind=leftouter ReconHosts on DeviceName
| join kind=leftouter VssTamper on DeviceName
| join kind=leftouter MassRename on DeviceName
| extend RiskScore =
iif(isnotempty(ReconTime), 30, 0) +
iif(isnotempty(VssTime), 40, 0) +
iif(isnotempty(RenameWindow), 50, 0) +
iif(FileName has_any ("rclone","psexec","psexesvc"), 25, 15)
| where RiskScore >= 40
| project DeviceName, AccountName, FileName, ProcessCommandLine, ReconTime, VssTime, VssCommand, RenameCount, RiskScore, ToolTime
| order by RiskScore desc, ToolTime asc
# N0N Rapid Triage & Hardening Script - Run on suspected hosts and domain controllers
# Checks: recent scheduled tasks (7d), shadow copy tampering, exposed RDP, suspicious services
$ErrorActionPreference = 'SilentlyContinue'
$Report = @()
$Cutoff = (Get-Date).AddDays(-7)
Write-Host "=== N0N RAPID TRIAGE - $(Get-Date) - $env:COMPUTERNAME ===" -ForegroundColor Cyan
# 1. Scheduled tasks created in last 7 days (N0N persistence mechanism)
Write-Host "`n[1] Scheduled tasks created since $Cutoff" -ForegroundColor Yellow
Get-ScheduledTask | ForEach-Object {
$info = $_ | Get-ScheduledTaskInfo
if ($info.LastRunTime -gt $Cutoff -or $_.Date -gt $Cutoff) {
$taskPath = $_.TaskPath + $_.TaskName
$action = ($_.Actions | Select-Object -First 1).Execute
if ($action -match 'powershell|cmd|wscript|rundll32|mshta|\.tmp|AppData|ProgramData') {
$Report += "[TASK] $taskPath -> $action"
Write-Host " SUSPICIOUS: $taskPath -> $action" -ForegroundColor Red
}
}
}
# 2. Volume Shadow Copy status (N0N deletes shadows pre-encryption)
Write-Host "`n[2] Volume Shadow Copy status" -ForegroundColor Yellow
$shadows = Get-CimInstance Win32_ShadowCopy
if (-not $shadows) {
$Report += "[VSS] NO SHADOW COPIES PRESENT - possible deletion"
Write-Host " WARNING: No shadow copies found - possible vssadmin deletion" -ForegroundColor Red
} else {
Write-Host " $($shadows.Count) shadow copies present (oldest: $($shadows | Sort-Object InstallDate | Select-Object -First 1).InstallDate)" -ForegroundColor Green
}
$vssEvents = Get-WinEvent -FilterHashtable @{LogName='Application'; ProviderName='VSS'; StartTime=$Cutoff} |
Where-Object { $_.Message -match 'deleted|delete' }
if ($vssEvents) { $Report += "[VSS] $($vssEvents.Count) shadow deletion events in 7d"; Write-Host " $($vssEvents.Count) VSS deletion events in last 7 days" -ForegroundColor Red }
# 3. Exposed RDP check (N0N brute-force vector)
Write-Host "`n[3] RDP exposure check" -ForegroundColor Yellow
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server').fDenyTSConnections -eq 0
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp').UserAuthentication
$rdpListener = Get-NetTCPConnection -LocalPort 3389 -State Listen
if ($rdpEnabled -and $rdpListener) {
$nlaStatus = if ($nla -eq 1) { 'NLA ON (ok)' } else { 'NLA OFF (RISK)' }
Write-Host " RDP LISTENING on 3389 - $nlaStatus" -ForegroundColor $(if ($nla -eq 1) {'Yellow'} else {'Red'})
$Report += "[RDP] Exposed, NLA=$nla"
$failed = Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=$Cutoff} |
Where-Object { $_.Message -match 'Logon Type:\s+(3|10)' } | Group-Object -Property {$_.Properties[19].Value} | Sort-Object Count -Descending | Select-Object -First 5
if ($failed) { Write-Host " Top failed-logon source IPs (7d):" -ForegroundColor Yellow; $failed | ForEach-Object { Write-Host " $($_.Name): $($_.Count) failures" } }
}
# 4. Suspicious services (PsExec clones, remote tools)
Write-Host "`n[4] Suspicious services" -ForegroundColor Yellow
$susServices = Get-CimInstance Win32_Service | Where-Object {
$_.PathName -match 'PSEXESVC|paexec|\\Temp\\|\\AppData\\|\\ProgramData\\.*\.exe' -and $_.PathName -notmatch 'Windows\\Temp\\(Adobe|Google|Microsoft)'
}
foreach ($s in $susServices) {
Write-Host " SUSPICIOUS SERVICE: $($s.Name) [$($s.State)] -> $($s.PathName)" -ForegroundColor Red
$Report += "[SVC] $($s.Name) -> $($s.PathName)"
}
# 5. Recently created local admins
Write-Host "`n[5] Local admin group changes" -ForegroundColor Yellow
$admins = Get-LocalGroupMember -Group 'Administrators'
foreach ($a in $admins) { Write-Host " Admin: $($a.Name) ($($a.ObjectClass))" }
Write-Host "`n=== SUMMARY: $($Report.Count) findings ===" -ForegroundColor Cyan
$Report | Out-File "$env:TEMP\n0n_triage_$($env:COMPUTERNAME)_$(Get-Date -Format 'yyyyMMdd_HHmm').txt"
if ($Report.Count -gt 0) { Write-Host "FINDINGS WRITTEN TO $env:TEMP - ESCALATE TO IR IMMEDIATELY" -ForegroundColor Red }
Incident Response Priorities — N0N Playbook
T-Minus Detection Checklist (Pre-Encryption Window)
N0N's 5–11 day dwell time is your intervention window. Hunt these in order of signal fidelity:
- vCenter/ESXi anomalies — new SSH enablement on ESXi hosts, unexpected
vim-cmd/esxcliexecution, datastore browsing by non-backup accounts, snapshot enumeration followed by deletion (CVE-2026-59310 post-exploitation). - Shadow copy deletion (
vssadmin delete shadows,bcdedit recoveryenabled no) — highest-fidelity pre-detonation signal; N0N executes this 1–6 hours before encryption. - Rclone/MEGA processes or large outbound transfers (>10GB to uncommon cloud ASNs) from servers that never normally transfer data.
- PsExec service installation (Event 7045) or
ADMIN$share access fanning out from a single workstation/server. - AD reconnaissance bursts —
nltest /dclist, AdFind, BloodHound/SharpHound LDAP query storms from a single account. - New local admin accounts or GPO changes outside change windows.
- EDR/AV tampering — service stops, exclusion additions, or uninstall attempts on security tooling (N0N uses
net stopand WMIC against common EDR services).
Critical Assets N0N Prioritizes for Exfiltration
- Financial/ERP data — general ledgers, wire transfer records, investor/client lists (per the Argentem Creek and STOKR targeting).
- HR & PII stores — payroll, benefits, identity documents (UFT and Ministry of Education pattern).
- Customer databases & e-commerce transaction records (Fanatics pattern — PCI-adjacent data drives negotiation leverage).
- Email archives of executives and legal counsel — used to identify sensitive matters for extortion pressure.
- Backup catalogs and credentials — to ensure recovery is impossible before detonation.
Containment Actions — Ordered by Urgency
- Isolate, don't power off suspected hosts — N0N's encryptor may trigger on shutdown detection; preserve RAM for forensic artifacts (Cobalt Strike beacons live in memory).
- Disable compromised accounts and force enterprise-wide credential reset, prioritizing VPN, service accounts, and domain admins. Assume Kerberos compromise — rotate
krbtgttwice if domain controller access is suspected. - Block exfiltration channels at the egress: MEGA, Rclone endpoints, Tor, and uncategorized cloud storage; rate-limit outbound >1GB transfers.
- Snapshot and isolate backup infrastructure — verify backups are offline/immutable and that backup service accounts are disabled until scoped.
- Patch or isolate edge appliances (vCenter, Check Point, Cisco FMC, ScreenConnect) before re-enabling remote access.
- Engage IR retainer and legal counsel early — N0N negotiates aggressively at 72 hours; having negotiators, counsel, and (where applicable) regulators lined up before the first contact materially improves outcomes.
Hardening Recommendations
Immediate (24 Hours)
- Patch or mitigate the five KEV CVEs — CVE-2026-59310 (vCenter), CVE-2026-50751 (Check Point), CVE-2026-20316 (Cisco FMC), CVE-2024-1708 (ScreenConnect), CVE-2026-48027 (Nx Console). If patching is impossible, isolate management interfaces behind jump hosts with MFA and ACL restrictions.
- Audit internet-facing RDP — disable or move behind VPN + NLA + MFA; block 3389 at the perimeter.
- Enable MFA on all remote access including VPN concentrators, BPO/vendor accounts, and ScreenConnect/AnyDesk instances; N0N's Transcom intrusion demonstrates third-party credentials are in scope.
- Deploy the Sigma rules and KQL query above; alert on shadow copy deletion as critical/24x7-pageable.
- Block macro execution from internet-sourced Office files (Mark-of-the-Web policy) and block OneNote attachments at the mail gateway if not business-required.
- Verify backup immutability and test one restoration today — assume the encryption wave is already inside a peer organization in your sector.
Short-Term (2 Weeks)
- Segment virtualization management planes — vCenter and ESXi management interfaces on isolated VLANs, accessible only from hardened PAWs; this directly breaks N0N's mass-encryption model.
- Implement egress data controls — DLP or proxy-based blocking of unsanctioned cloud storage (MEGA, Rclone remotes) and alerting on anomalous outbound volume per host baseline.
- Deploy honeytokens and deception credentials — N0N's reconnaissance phase reliably touches decoy AD objects, providing high-fidelity early warning inside the dwell window.
- Tier-0 hardening — enforce Protected Users for admins, gMSA for service accounts, LAPS for local admin passwords, and disable NTLMv1/legacy IKEv1 (the Check Point CVE exploits IKEv1 key exchange).
- Third-party/BPO access review — inventory all vendor accounts with network access, enforce least privilege, JIT access, and session recording. The PayPal-support-via-Transcom intrusion is the campaign's clearest lesson: your outsourcer's compromise is your breach notification.
- Tabletop the 72-hour negotiation scenario — pre-authorize decision trees for ransom negotiation, disclosure obligations (SEC, GDPR, LGPD given the geographic spread), and law enforcement engagement across relevant jurisdictions.
This briefing is based on live leak site telemetry collected 2026-09-22. Victim postings on criminal leak sites do not constitute confirmation of breach claims; organizations named should be considered at-risk pending their own verification. Security Arsenal does not engage with threat actors.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.