Classification: TLP:CLEAR | Publication Date: 2026-09-21 | Source: Security Arsenal dark web monitoring (leak site telemetry via ransomware.live) + CISA KEV correlation
Executive Summary
Security Arsenal's underground collection infrastructure has confirmed a sharp escalation in N0N ransomware activity. Between 2026-09-18 and 2026-09-20, the group published 11 victim organizations across 8 countries to its Tor-based leak site — a posting cadence that indicates either a coordinated multi-access campaign or the delayed bulk disclosure of intrusions executed over the preceding weeks.
The victim set is deliberately diversified: a global sports commerce platform (Fanatics), a national ISP (Inter, Venezuela), a BPO supporting PayPal operations (Transcom WorldWide, Sweden), the Argentine Ministry of Education, AstraZeneca Türkiye, a digital securities platform (STOKR, Luxembourg), and a US teachers' union. This is not opportunistic single-sector spraying — it reads as an access-broker-fed pipeline monetizing whatever perimeter vulnerabilities are currently yielding.
Organizations in financial services, healthcare, retail/e-commerce, education, and government should treat this bulletin as an active threat and execute the 24-hour hardening actions in Section 7 immediately.
1. Threat Actor Profile — N0N
Analyst note: N0N is a comparatively low-signature operation with limited public reporting. The profile below combines direct leak-site observation with pattern-matching against similar mid-tier crews. Confidence levels are marked.
| Attribute | Assessment | Confidence |
|---|---|---|
| Aliases | N0N; occasionally stylized "NON" / "N0N Team" on leak infrastructure and negotiation portals | Moderate |
| Operating model | Closed/semi-closed group with evidence of purchased initial access (diverse, unrelated victims in a compressed window is a classic access-broker consumption pattern) rather than a large open RaaS affiliate program | Moderate |
| Ransom demands | Victim-scaled; based on victim revenue profile in this campaign, demands are assessed in the low-to-mid six figures USD for mid-market targets, scaling to seven figures for the enterprise/telecom victims | Low-Moderate |
| Initial access (assessed) | Edge/VPN appliance exploitation (consistent with the Check Point, Cisco FMC, and VMware vCenter KEV entries below), RDP exposure, and phishing with macro-laden documents. The breadth of geographies argues against a single vector | Moderate |
| Extortion model | Double extortion: data theft followed by leak-site publication with countdown timers; victims in this batch appear to have been posted after non-payment or stalled negotiation | High (observed) |
| Dwell time (assessed) | Bulk posting of 11 victims in a 4-day window suggests staged intrusions with dwell times likely in the 2–6 week range before disclosure — giving defenders a meaningful detection window pre-encryption | Moderate |
Structural indicator worth tracking: The presence of a BPO (Transcom WorldWide) explicitly framed as "PayPal support operations" shows N0N deliberately names upstream clients to increase pressure. Supply-chain and third-party victimization is part of their leverage model — monitor your vendors, not just your own perimeter.
2. Current Campaign Analysis
2.1 Sector Targeting
| Sector | Victims in Batch | Notable Entries |
|---|---|---|
| Financial Services | 3 | Transcom WorldWide (PayPal ops, SE), Argentem Creek Partners (US), STOKR (LU) |
| Education | 2 | United Federation of Teachers (US), BeLi Teacher/FSC (VN) |
| Technology | 1 | Inter — Venezuela's largest ISP |
| Retail & E-Commerce | 1 | Fanatics (US, global) |
| Healthcare | 1 | AstraZeneca Türkiye |
| Government & Defense | 1 | Ministry of Education — Argentina |
| Professional Services | 1 | Konnatus (BR) |
| Other | 1 | Vietnamese betting operator (GC789 network) |
Financial services weighting (3/11) plus a payment-adjacent BPO suggests payment data and financial PII are priority exfiltration targets — consistent with monetization beyond the ransom itself (fraud resale).
2.2 Geographic Concentration
US (3) and Vietnam (2) lead, with single victims in VE, SE, AR, TR, LU, and BR. This is opportunistic global reach with a US-center of gravity — typical of groups buying access from brokers whose inventory skews to English-speaking and Latin American markets. The Latin American cluster (VE, AR, BR) in one batch is notable and may reflect a single broker's regional access dump.
2.3 Victim Profile
- Size range: From mid-market legal/education services to a multinational telecom and a global retail platform. No minimum-revenue floor is evident — N0N is not following the "big game only" discipline of top-tier crews.
- Revenue exposure: Estimated victim revenues range from low eight figures (regional services firms) to nine figures+ (Fanatics, Inter). This breadth reinforces the access-broker hypothesis: they take what the market sells.
- Cloud footprint: At least one victim (BeLi Teacher/FSC) is explicitly tagged as AWS-hosted, indicating cloud tenant compromise is in-scope for this group, not just on-prem encryption.
2.4 Posting Frequency / Escalation Pattern
- Baseline: Low trickle historically.
- Current: 10 postings on 2026-09-18 alone, plus Fanatics on 2026-09-20 — a ~10x burst over baseline.
- Interpretation: Bulk dumps of this shape usually mean one of three things: (a) a negotiation batch timed out simultaneously, (b) the group is clearing inventory before rebranding/infrastructure migration, or (c) a new access pipeline came online 3–6 weeks ago. Defenders should assume (c) until disproven and hunt accordingly — more victims from this wave are likely already compromised and not yet posted.
2.5 CVE Correlation (CISA KEV — Confirmed Ransomware Use)
The following actively exploited vulnerabilities align with N0N's assessed edge-device and remote-access tradecraft. Patch status on these should be verified this week:
| CVE | Product | KEV Added | Relevance to N0N Campaign |
|---|---|---|---|
| CVE-2026-59310 | Broadcom VMware vCenter (path traversal) | 2026-08-18 | Direct path to hypervisor-level control — enables mass VM encryption, the highest-impact ransomware outcome |
| CVE-2026-20316 | Cisco Secure FMC (hard-coded password) | 2026-07-29 | Firewall management plane takeover; gives both access and blind-spot creation |
| CVE-2026-50751 | Check Point Security Gateway (improper auth, IKEv1) | 2026-06-08 | VPN gateway bypass — the single most consistent initial-access family in 2025–2026 ransomware telemetry |
| CVE-2026-48027 | Nx Console (embedded malicious code) | 2026-05-27 | Supply-chain/dev-tooling vector; plausible entry into technology-sector victims |
| CVE-2024-1708 | ConnectWise ScreenConnect (path traversal → RCE) | 2026-04-28 | RMM tooling abuse; enables both initial access and persistent legitimate-looking remote control |
Priority correlation: CVE-2026-50751 (Check Point IKEv1 auth bypass) and CVE-2026-59310 (vCenter) form the most dangerous pairing in this set — perimeter entry followed by virtualization-layer detonation. If you run both, treat patching as an emergency change, not a scheduled one.
3. Detection Engineering
3.1 Sigma Rules
The following rules target the TTP chain assessed for N0N: phishing/macro execution at the endpoint, PsExec-style lateral movement, and pre-encryption shadow copy destruction.
---
title: Office Macro Spawning Suspicious Child Process - N0N Initial Access
id: 8f3a2c11-n0n1-4b7e-9a01-20260921a001
status: experimental
description: Detects Microsoft Office applications spawning scripting or LOLBin child processes, consistent with macro-based phishing payloads used for initial access in ransomware campaigns matching N0N's assessed tradecraft.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/21
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate Office add-ins invoking script engines
level: high
tags:
- attack.initial_access
- attack.t1566.001
- attack.t1204.002
---
title: Remote Service Creation via PsExec or WMI Pattern - N0N Lateral Movement
id: 8f3a2c11-n0n1-4b7e-9a01-20260921a002
status: experimental
description: Detects new service installations with names or binary paths consistent with PsExec-style lateral movement and ransomware staging (random service names, ADMIN$ paths, user-writable directories).
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/21
logsource:
product: windows
service: system
definition: Event ID 7045 - Service Installed
detection:
selection:
EventID: 7045
filter_suspicious_path:
ImagePath|contains:
- '\ADMIN$\'
- '\Users\Public\'
- '\AppData\Local\Temp\'
- '\ProgramData\'
- 'PSEXESVC'
filter_random_name:
ServiceName|re: '^[A-Za-z0-9]{4,8}$'
condition: selection and (filter_suspicious_path or filter_random_name)
falsepositives:
- Legitimate software deployment tools (SCCM, PDQ) - baseline and exclude known deployment accounts
level: high
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1569.002
- attack.t1543.003
---
title: Volume Shadow Copy Deletion - Pre-Encryption Staging Indicator
id: 8f3a2c11-n0n1-4b7e-9a01-20260921a003
status: experimental
description: Detects deletion or resize of Volume Shadow Copies via vssadmin, wmic, PowerShell, or bcdedit - a near-universal pre-encryption behavior across ransomware families including those matching N0N's leak profile.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/21
logsource:
category: process_creation
product: windows
detection:
selection_vssadmin:
Image|endswith: '\vssadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'resize shadowstorage'
selection_wmic:
Image|endswith: '\wmic.exe'
CommandLine|contains: 'shadowcopy'
selection_ps:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'Get-WmiObject Win32_Shadowcopy'
- 'Get-CimInstance Win32_ShadowCopy'
- '.Delete()'
selection_bcdedit:
Image|endswith: '\bcdedit.exe'
CommandLine|contains: 'recoveryenabled'
condition: 1 of selection_*
falsepositives:
- Backup software maintenance (rare for delete operations)
- IT disk-space remediation scripts
level: critical
tags:
- attack.impact
- attack.t1490
- attack.t1486
3.2 KQL — Microsoft Sentinel Pre-Ransomware Staging Hunt
This query hunts the 48-hour staging window N0N's assessed dwell time implies: new admin-share service installs followed by mass file access, archive-tool execution (data staging for exfil), or shadow copy tampering on the same host.
// N0N Pre-Ransomware Staging Hunt - Security Arsenal
// Looks for correlated staging behaviors on a single device within 48h:
// remote service install + archiving tools + shadow copy tampering + bulk file access
let Lookback = 14d;
let CorrelationWindow = 48h;
let ServiceInstalls =
SecurityEvent
| where TimeGenerated > ago(Lookback)
| where EventID == 7045
| where ServiceFileName has_any ("ADMIN$", "Users\\Public", "AppData\\Local\\Temp", "ProgramData", "PSEXESVC")
| project ServiceTime=TimeGenerated, Computer, ServiceName, ServiceFileName, Account;
let ArchiveStaging =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName has_any ("7z.exe", "7za.exe", "rar.exe", "winrar.exe")
or ProcessCommandLine has_any (" a -", " -p", "vssadmin delete", "shadowcopy delete", "resize shadowstorage", "recoveryenabled no")
| project StageTime=TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessAccountName;
let MassFileAccess =
DeviceFileEvents
| where TimeGenerated > ago(Lookback)
| where ActionType == "FileRenamed"
| summarize RenamedCount = count(), DistinctExtensions = dcount(parse_path(FileName).Extension) by DeviceName, bin(TimeGenerated, 1h)
| where RenamedCount > 500
| project RenameWindow=TimeGenerated, DeviceName, RenamedCount, DistinctExtensions;
ServiceInstalls
| join kind=inner (ArchiveStaging) on $left.Computer == $right.DeviceName
| where abs(datetime_diff('minute', StageTime, ServiceTime)) <= (CorrelationWindow / 1h) * 60
| join kind=leftouter (MassFileAccess) on $left.Computer == $right.DeviceName
| project Computer, ServiceTime, ServiceName, ServiceFileName, Account,
StageTime, FileName, ProcessCommandLine,
RenameWindow, RenamedCount, DistinctExtensions
| order by Computer asc, ServiceTime asc
Tuning guidance: The RenamedCount > 500 threshold assumes file servers; drop to 100 for endpoints. Baseline your software deployment accounts and exclude them from the 7045 branch to cut noise.
3.3 PowerShell — Rapid Triage & Hardening Script
Run on suspected hosts and domain controllers during triage of this campaign's indicators:
# Security Arsenal - N0N Campaign Rapid Triage Script
# Run elevated. Read-only: collects indicators, makes no changes.
# 2026-09-21
$report = @()
$cutoff = (Get-Date).AddDays(-7)
Write-Host "[1/5] Scheduled tasks created in last 7 days (persistence check)..." -ForegroundColor Cyan
$tasks = Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt $cutoff } |
Select-Object TaskName, TaskPath, Date, @{N='Action';E={($_.Actions | ForEach-Object { $_.Execute + ' ' + $_.Arguments }) -join '; '}}
$report += "=== NEW SCHEDULED TASKS (7d) ===`n" + ($tasks | Format-List | Out-String)
Write-Host "[2/5] Volume Shadow Copy status (pre-encryption tampering check)..." -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
$shadowStorage = Get-CimInstance Win32_ShadowStorage -ErrorAction SilentlyContinue
$report += "=== SHADOW COPIES PRESENT: $($shadows.Count) ===`n" +
"=== SHADOW STORAGE VOLUMES: $($shadowStorage.Volume.Count) ===`n"
if ($shadows.Count -eq 0) { $report += "!!! WARNING: NO SHADOW COPIES FOUND - possible anti-recovery action !!!`n" }
Write-Host "[3/5] Recent 7045 service installs (PsExec/lateral movement check)..." -ForegroundColor Cyan
$svcs = Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=$cutoff} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, @{N='Service';E={$_.Properties[0].Value}}, @{N='Path';E={$_.Properties[1].Value}}, @{N='Account';E={$_.Properties[4].Value}}
$report += "=== SERVICE INSTALLS (7d) ===`n" + ($svcs | Format-Table -AutoSize | Out-String)
Write-Host "[4/5] RDP exposure + NLA status (initial access surface)..." -ForegroundColor Cyan
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server').fDenyTSConnections -eq 0
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -ErrorAction SilentlyContinue).UserAuthentication
$rdpListen = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
$report += "=== RDP ENABLED: $rdpEnabled | NLA: $nla | LISTENING: $($null -ne $rdpListen) ===`n"
Write-Host "[5/5] Failed logons (4625) - brute force signal, last 24h..." -ForegroundColor Cyan
$fails = Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} -ErrorAction SilentlyContinue
$topFails = $fails | Group-Object { $_.Properties[19].Value } | Sort-Object Count -Descending | Select-Object -First 10 Name, Count
$report += "=== TOP FAILED LOGON SOURCES (24h): $($fails.Count) total ===`n" + ($topFails | Format-Table | Out-String)
$outFile = "$env:TEMP\N0N_Triage_$(Get-Date -Format 'yyyyMMdd_HHmmss').txt"
$report | Out-File $outFile -Encoding UTF8
Write-Host "`nTriage report written to: $outFile" -ForegroundColor Green
if (-not $rdpEnabled -or $nla -eq 1) { Write-Host "RDP posture OK." } else { Write-Host "ACTION: RDP exposed without NLA - remediate immediately." -ForegroundColor Red }
4. Incident Response Priorities
4.1 T-Minus Detection Checklist (Before Encryption Fires)
Based on the assessed 2–6 week dwell window, these signals precede detonation — hunt them now, not after a ransom note:
- Edge device anomalies: New local accounts or config changes on Check Point / Cisco FMC appliances; IKEv1 negotiation failures from single sources (CVE-2026-50751 probing)
- vCenter irregularities: Unauthenticated or unusual file-read patterns against vCenter (CVE-2026-59310), unexpected snapshot deletions, new sessions from non-jump-host IPs
- RMM/tool sprawl: ScreenConnect, AnyDesk, or similar tooling present that IT did not deploy (CVE-2024-1708 fallout and affiliate tooling)
- Staging artifacts:
7z/rarexecution on servers, multi-GB archives inProgramDataor user profiles,rcloneor MEGA/paste-site egress - Recon bursts:
net group "Domain Admins" /domain,nltest, BloodHound/SharpHound LDAP query volume from a single workstation - Backup interaction: Any access to backup consoles (Veeam, Commvault) from non-backup-admin accounts — a strong T-72h indicator
4.2 Critical Assets N0N Prioritizes for Exfiltration
From the current victim set's sector composition, assume targeting priority on:
- Payment and financial data (Fanatics, Transcom/PayPal adjacency) — cardholder data, transaction records, support-ticket PII
- Identity-verifiable PII at scale (ministry, teachers' union, ISP subscriber data) — high resale value
- Legal/M&A documents (Argentem Creek, STOKR, Konnatus) — leverage for negotiation pressure
- Healthcare/regulated data (AstraZeneca Türkiye) — regulatory fine exposure multiplies extortion leverage
4.3 Containment Actions — Ordered by Urgency
- Isolate edge infrastructure: If any Check Point/Cisco FMC/vCenter compromise indicator is confirmed, take the management interfaces off reachable networks first — this severs both C2 and the mass-encryption path.
- Disable the suspected identity plane: Force password reset for all accounts observed in lateral movement; revoke active Kerberos tickets (
klist purgeen masse via GPO or password-reset double-tap); disable the foothold account. - Kill egress at the proxy/firewall: Block unsanctioned file-sharing and paste domains, Tor, and known exfil ASNs; ransomware crews depend on exfil completing before encryption — cutting egress degrades their leverage even mid-incident.
- Snapshot and isolate backup infrastructure: Take backup consoles offline from the production network; verify immutable/offline copies exist before they become targets.
- Segment the virtualization layer: Isolate vCenter/ESXi management VLANs; this is where a single-host compromise becomes an enterprise-ending event.
- Preserve evidence before remediation: Memory captures and firewall/VPN logs from edge devices rotate fast — collect before patching.
- Engage external IR and legal/comms: Given this group's third-party naming behavior (the Transcom/PayPal framing), assume your clients will be named on the leak site even if your data exposure is indirect — pre-draft notification posture.
5. Hardening Recommendations
Immediate (24 Hours)
- Patch the KEV five, in this order: CVE-2026-50751 (Check Point) → CVE-2026-59310 (vCenter) → CVE-2026-20316 (Cisco FMC) → CVE-2024-1708 (ScreenConnect) → CVE-2026-48027 (Nx Console — also audit developer workstations for the malicious package version).
- Disable IKEv1 on Check Point gateways where not operationally required; force IKEv2. If patching CVE-2026-50751 can't complete in 24h, this is the compensating control.
- Verify MFA on all remote access — VPN, VDI, RDP gateways, and especially third-party/BPO connections into your environment (the Transcom lesson).
- Confirm shadow copy integrity and offline backups on all Tier-0/Tier-1 assets; a host with zero shadow copies and recent 7045 events is a pre-detonation host.
- Block macro execution from internet-sourced Office files via Mark-of-the-Web GPO if not already enforced.
- Deploy the Sigma rules above and run the KQL hunt across the last 14 days — this group's dwell time means the intrusion may already be inside your window.
Short-Term (2 Weeks)
- Remove management planes from general network reachability: vCenter, FMC, backup consoles, and hypervisor management behind dedicated jump hosts with PAW enforcement and session recording.
- Implement Tiered administration if not present: N0N-style access-broker intrusions convert to enterprise compromise via credential overlap between workstation admins and domain admins — eliminate it.
- Deploy canary files and decoy shares on file servers; rename-touch on canaries at volume is a sub-5-minute encryption tripwire.
- Egress filtering by default-deny for server VLANs — servers should not initiate arbitrary HTTPS to the internet; this breaks most exfil tooling outright.
- Vendor/third-party access audit: Inventory every BPO, MSP, and support vendor with network or data access; enforce conditional access, device compliance, and least-privilege scoping on each. This campaign demonstrates that your vendors' compromise becomes your leak-site listing.
- Tabletop the leak-site scenario: Legal, comms, and executives should rehearse a double-extortion disclosure — including the third-party naming angle — before it happens.
Analyst's Closing Note
N0N's September burst has the fingerprint of a group mid-scaling: new access supply, aggressive multi-sector disclosure, and third-party leverage tactics borrowed from larger crews. The 2–6 week assessed dwell time is the defender's advantage — the next batch of victims from this campaign wave is likely already compromised and within the detection window. The hunt queries in this briefing are designed for exactly that gap.
Security Arsenal will continue monitoring N0N's leak infrastructure and will publish updates as new victims and TTP shifts are observed.
Related Resources
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.