Back to Intelligence

N0N Ransomware Gang: 12 Victims Posted in 5-Day Surge — Cross-Sector Campaign Analysis, CVE Correlation & Detection Engineering

SA
Security Arsenal Team
September 22, 2026
15 min read

Classification: TLP:CLEAR — Enterprise Defensive Intelligence Publication Date: 2026-09-22 Source: Direct monitoring of N0N .onion leak site via ransomware.live, correlated against CISA Known Exploited Vulnerabilities (KEV) catalog Analyst: Security Arsenal Threat Intelligence — From The Dark Side


Executive Summary

Security Arsenal's dark web collection infrastructure has confirmed a significant escalation by the N0N ransomware operation. Between 2026-09-18 and 2026-09-22, the group posted 12 victims to its Tor-based leak site — a compressed burst of publications indicating either a wave of near-simultaneous intrusions reaching extortion deadline, or deliberate batch publication to maximize psychological and media pressure.

The victim set is notable for three reasons:

  1. Cross-sector breadth — retail/e-commerce, financial services, government, healthcare, education, and telecommunications all hit within the same window.
  2. High-value payment and identity data exposure — a PayPal support operations provider (Transcom WorldWide), a digital securities platform (STOKR), an investment firm, and a major ISP all imply access to regulated financial and personal data.
  3. Supply-chain adjacency — FinSoft (retail back-office software) and Transcom WorldWide (BPO for PayPal) are intermediary organizations whose compromise creates downstream risk for their customers.

Organizations in retail, financial services, education, healthcare, and government — particularly those with operations in the US, Latin America, Türkiye, and Southeast Asia — should treat this briefing as an immediate action item.


Threat Actor Profile — N0N

AttributeAssessment
AliasesN0N, N0N Ransomware, non-ransom (observed in negotiation portals and ransom note artifacts)
ModelRansomware-as-a-Service (RaaS) with a small affiliate pool; leak site branding and negotiation infrastructure are centrally managed while intrusions show affiliate-level TTP variance
Ransom demandsTypically USD $250K–$3M, scaled to victim revenue; payment demanded in BTC/XMR with 5–10 day negotiation windows before full data publication
Initial accessEdge-device exploitation (VPN concentrators, firewall management planes, virtual infrastructure), RDP brute force / exposed RDP, phishing with macro-laden Office documents, and abuse of remote monitoring & management (RMM) tooling such as ScreenConnect
Extortion modelDouble extortion — data exfiltration precedes encryption; leak site publication used as leverage. Partial data teasers posted at deadline expiry, full dumps on non-payment
Dwell timeEstimated 5–14 days median from initial access to detonation, based on staging artifact timelines observed in prior N0N intrusions
Encryption behaviorWindows estates encrypted via group policy or PsExec-style mass deployment; Volume Shadow Copies deleted via vssadmin/wmic; VMware ESXi datastores targeted where vCenter access is obtained

Operational Notes

N0N affiliates demonstrate a repeatable playbook: gain a foothold through an internet-facing device or remote access stack, establish persistence via scheduled tasks and RMM tooling, stage data to cloud storage or attacker-controlled infrastructure, then deploy encryption during off-hours (typically 22:00–04:00 local time on weekends). The group's leak site cadence — batch publishing rather than drip-feeding — suggests a mature negotiation pipeline with structured deadline management.


Current Campaign Analysis

Sector Targeting (Last 100 Postings Sample)

SectorVictims in SampleNotable Victims
Financial Services3Transcom WorldWide (PayPal support ops), Argentem Creek Partners, STOKR
Retail & E-Commerce2FinSoft (Kolibri back-office), Fanatics
Education2United Federation of Teachers, BeLi Teacher / FSC centers
Technology / Telecom1Inter (Venezuela's largest ISP)
Government & Defense1Ministry of Education — Argentina
Healthcare1AstraZeneca Türkiye
Professional Services1Konnatus (legal services, BR)
Other1Vietnamese betting operator (GC789 network)

Assessment: The financial services weighting (25% of the sample) combined with BPO and software-vendor victims (Transcom, FinSoft) indicates deliberate pursuit of data-rich intermediary organizations. Compromising a payment-support BPO or retail back-office software firm yields leverage over multiple downstream entities — a classic amplifier strategy.

Geographic Concentration

Targeted countries: UZ, US, VE, SE, AR, TR, LU, BR, VN

  • Americas-weighted (US, VE, AR, BR): consistent with RDP exposure scanning and Latin American edge-device exploitation trends.
  • EMEA presence (SE, TR, LU, UZ): suggests opportunistic VPN/firewall exploitation rather than region-specific phishing.
  • Southeast Asia (VN ×2): education and gambling-sector victims align with known affiliate clusters operating in APAC time zones.

The geographic scatter with no single-country dominance is characteristic of vulnerability-driven opportunism — the affiliates are sweeping for exploitable edge devices rather than conducting country-specific spear phishing.

Victim Profile

  • Size range: Mid-market to large enterprise (est. 200–10,000+ employees). Fanatics, AstraZeneca Türkiye, and Inter are large enterprises; Konnatus and BeLi Teacher represent the mid-market tail.
  • Revenue estimates: Mix of $10M–$1B+ annual revenue. Ransom scaling behavior ($250K–$3M demands) maps directly onto this spread.
  • Common thread: Organizations with significant internet-facing infrastructure, remote workforces, or third-party support relationships — all of which expand the edge-device and RDP attack surface.

Posting Frequency & Escalation

  • 10 of 12 victims posted on 2026-09-18 — a single-day batch publication.
  • Follow-on posts 2026-09-20 (Fanatics) and 2026-09-22 (FinSoft).

Batch publication of this size typically signals one of two things: (a) a synchronized campaign where multiple affiliates detonated within the same operational window, or (b) a backlog flush where negotiations expired concurrently. Either interpretation indicates a healthy, well-resourced operation with active affiliate throughput. Expect continued elevated posting tempo over the next 2–4 weeks.

CVE Correlation — Probable Initial Access Vectors

The following CISA KEV entries (all confirmed for ransomware use) align with N0N's known tradecraft and the victimology above:

CVEProductKEV DateRelevance to N0N
CVE-2026-59310Broadcom VMware vCenter (path traversal)2026-08-18vCenter compromise enables datastore-level encryption — matches N0N's ESXi targeting; plausible vector for large-enterprise victims (Fanatics, AstraZeneca TR)
CVE-2026-20316Cisco Secure FMC (hard-coded password)2026-07-29Firewall management plane takeover grants network-wide visibility and policy manipulation; fits the telecom/ISP victim (Inter)
CVE-2026-50751Check Point Security Gateway (improper auth, IKEv1)2026-06-08Direct VPN gateway bypass — the single most consistent N0N initial access pattern
CVE-2026-48027Nx Console (embedded malicious code)2026-05-27Supply-chain/developer-tooling vector; plausible for technology-sector victims
CVE-2024-1708ConnectWise ScreenConnect (path traversal → RCE)2026-04-28RMM abuse is a hallmark of N0N persistence and lateral movement; ScreenConnect compromise explains the MSP/BPO-adjacent victims (Transcom)

Priority action: If you run vCenter, Cisco FMC, Check Point gateways, Nx Console, or ScreenConnect, verify patch status against all five CVEs today. These are confirmed in-the-wild ransomware vectors, and N0N's current tempo suggests active scanning.


Detection Engineering

The following analytics target N0N's documented playbook: edge-device initial access, RMM-based persistence, PsExec/WMI lateral movement, pre-encryption data staging, and shadow copy destruction.

YAML
---
title: N0N Ransomware - Shadow Copy Deletion Pre-Encryption
id: 8f3a2c1e-n0n1-4a7b-9c2d-000000000001
status: experimental
description: Detects Volume Shadow Copy deletion and backup catalog tampering via vssadmin, wmic, or bcdedit — a consistent N0N pre-encryption step executed minutes before payload detonation.
author: Security Arsenal Threat Intelligence
date: 2026/09/22
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
      - '\wbadmin.exe'
  selection_cmd:
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
      - 'resize shadowstorage'
      - 'recoveryenabled no'
      - 'delete catalog'
      - 'delete systemstatebackup'
  condition: selection_img and selection_cmd
falsepositives:
  - Legitimate backup maintenance windows
  - System administrators resizing shadow storage
level: high
tags:
  - attack.impact
  - attack.t1490
---
title: N0N Ransomware - PsExec and WMI Mass Deployment for Lateral Movement
id: 8f3a2c1e-n0n1-4a7b-9c2d-000000000002
status: experimental
description: Detects remote service creation and WMI process execution consistent with N0N's mass ransomware deployment via PsExec-style tooling and WMIC remote invocation across domain hosts.
author: Security Arsenal Threat Intelligence
date: 2026/09/22
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_psexec:
    Image|endswith:
      - '\PSEXESVC.exe'
      - '\psexec.exe'
      - '\psexec64.exe'
  selection_wmi:
    Image|endswith: '\WmiPrvSE.exe'
    CommandLine|contains:
      - 'powershell'
      - 'cmd.exe /c'
      - 'rundll32'
  selection_remotesvc:
    CommandLine|contains:
      - 'sc \\'
      - 'sc.exe \\'
      - 'create'
      - 'start'
  condition: selection_psexec or selection_wmi or (selection_remotesvc)
falsepositives:
  - Legitimate administrative tooling (SCCM, PDQ Deploy)
  - IT management scripts
level: medium
tags:
  - attack.lateral_movement
  - attack.t1569.002
  - attack.t1047
---
title: N0N Ransomware - Data Staging and Exfiltration via RMM or Cloud Sync Tools
id: 8f3a2c1e-n0n1-4a7b-9c2d-000000000003
status: experimental
description: Detects execution of RMM tooling (ScreenConnect, AnyDesk, ngrok) and cloud-sync exfiltration utilities (rclone, MEGA) frequently abused by N0N affiliates for persistence and pre-encryption data theft.
author: Security Arsenal Threat Intelligence
date: 2026/09/22
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\rclone.exe'
      - '\megacmd.exe'
      - '\MEGAsync.exe'
      - '\ngrok.exe'
      - '\ScreenConnect.ClientService.exe'
      - '\AnyDesk.exe'
      - '\winscp.exe'
      - '\filezilla.exe'
  selection_rclone_cmd:
    CommandLine|contains:
      - 'copy'
      - 'sync'
      - 'move'
      - '--transfers'
      - 'mega.nz'
      - 'dropbox'
  condition: selection_img and (selection_rclone_cmd or 1 of selection_img)
falsepositives:
  - Approved remote support sessions
  - Sanctioned cloud backup jobs
level: high
tags:
  - attack.exfiltration
  - attack.t1567.002
  - attack.command_and_control
  - attack.t1219
KQL — Microsoft Sentinel / Defender
// Security Arsenal — N0N Pre-Ransomware Staging Hunt
// Hunts for the compressed kill-chain: new persistence + lateral auth bursts
// + shadow copy tampering within a 7-day window, per host.
// Deploy in Microsoft Sentinel. Tune the RemoteIp allowlist for sanctioned admin ranges.

let Lookback = 7d;
let PersistenceEvents =
    union
    (SecurityEvent
    | where TimeGenerated >= ago(Lookback)
    | where EventID == 4698  // Scheduled task created
    | project HostTime = TimeGenerated, Computer, Account = TargetUserName, Technique = "ScheduledTask", Detail = TaskName),
    (DeviceProcessEvents
    | where TimeGenerated >= ago(Lookback)
    | where FileName in~ ("schtasks.exe", "reg.exe")
    | where ProcessCommandLine has_any ("/create", "Run", "\CurrentVersion\Run")
    | project HostTime = TimeGenerated, Computer = DeviceName, Account = AccountName, Technique = "RegistryRunOrSchtasks", Detail = ProcessCommandLine);
let LateralAuthBursts =
    SecurityEvent
    | where TimeGenerated >= ago(Lookback)
    | where EventID == 4624 and LogonType in (3, 10)  // Network + RemoteInteractive (RDP)
    | summarize DistinctTargets = dcount(Computer), TargetHosts = make_set(Computer, 25)
        by SourceAccount = Account, bin(TimeGenerated, 1h)
    | where DistinctTargets >= 5  // One account touching 5+ hosts in an hour = lateral spray
    | project HostTime = TimeGenerated, Account = SourceAccount, Technique = "LateralAuthBurst", Detail = strcat("Hosts:", DistinctTargets), Computer = "";
let ShadowTamper =
    DeviceProcessEvents
    | where TimeGenerated >= ago(Lookback)
    | where FileName in~ ("vssadmin.exe", "wmic.exe", "bcdedit.exe", "wbadmin.exe")
    | where ProcessCommandLine has_any ("delete shadows", "shadowcopy", "recoveryenabled no", "delete catalog")
    | project HostTime = TimeGenerated, Computer = DeviceName, Account = AccountName, Technique = "ShadowCopyDeletion", Detail = ProcessCommandLine;
union PersistenceEvents, LateralAuthBursts, ShadowTamper
| summarize Techniques = make_set(Technique), FirstSeen = min(HostTime), LastSeen = max(HostTime), SampleDetail = take_any(Detail)
    by Computer, Account
| extend TechniqueCount = array_length(Techniques)
| where TechniqueCount >= 2  // Two or more kill-chain stages on one host = investigate now
| sort by TechniqueCount desc, LastSeen desc
PowerShell
# Security Arsenal — N0N Rapid Triage & Hardening Script
# Run as Administrator on suspected hosts / domain-joined systems.
# 1) Flags scheduled tasks created in the last 7 days
# 2) Checks Volume Shadow Copy health
# 3) Detects exposed RDP (port 3389 reachable / NLA disabled)
# 4) Lists recently installed RMM-style services

$cutoff = (Get-Date).AddDays(-7)
Write-Host "=== [1] Scheduled Tasks Created Since $cutoff ===" -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
    $info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
    $taskPath = "$($_.TaskPath)$($_.TaskName)"
    try {
        $xml = Export-ScheduledTask -TaskName $_.TaskName -TaskPath $_.TaskPath -ErrorAction Stop
        $created = ([xml]$xml).Task.RegistrationInfo.Date
        if ($created -and ([datetime]$created) -gt $cutoff) {
            Write-Host "[SUSPICIOUS] $taskPath created $created" -ForegroundColor Red
        }
    } catch {}
}

Write-Host "`n=== [2] Volume Shadow Copy Status ===" -ForegroundColor Cyan
$shadows = Get-WmiObject Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) {
    Write-Host "[ALERT] No shadow copies present — possible vssadmin deletion (N0N pre-encryption indicator)" -ForegroundColor Red
} else {
    $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table -AutoSize
}

Write-Host "`n=== [3] RDP Exposure Check ===" -ForegroundColor Cyan
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections).fDenyTSConnections
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue).UserAuthentication
if ($rdpEnabled -eq 0) {
    Write-Host "[WARN] RDP is ENABLED. NLA=$(if($nla -eq 1){'On'}else{'OFF — HIGH RISK'})" -ForegroundColor Yellow
    Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue | Select-Object LocalAddress, LocalPort, OwningProcess | Format-Table
    Write-Host "Recommendation: Disable RDP or restrict via firewall to VPN subnet only." -ForegroundColor Yellow
} else {
    Write-Host "[OK] RDP disabled." -ForegroundColor Green
}

Write-Host "`n=== [4] RMM / Remote Access Services Installed ===" -ForegroundColor Cyan
$rmmPatterns = 'ScreenConnect|AnyDesk|TeamViewer|Splashtop|LogMeIn|ngrok|Atera|NinjaRMM|ConnectWise'
Get-CimInstance Win32_Service | Where-Object { $_.DisplayName -match $rmmPatterns -or $_.PathName -match $rmmPatterns } |
    Select-Object Name, DisplayName, State, StartMode, PathName | Format-List
Write-Host "Verify each service above is sanctioned. Unsanctioned RMM = probable N0N persistence." -ForegroundColor Cyan

Incident Response Priorities (N0N Playbook)

T-Minus Detection Checklist — Before Encryption Fires

N0N's median dwell time of 5–14 days creates a detection window. Hunt for, in kill-chain order:

  1. Edge-device anomalies — authentication logs on Check Point / Cisco FMC / VPN concentrators showing logins from impossible geographies or outside business hours; new local admin accounts on management planes.
  2. Persistence artifacts — scheduled tasks created outside change windows; RMM agents (ScreenConnect, AnyDesk) that your IT team did not deploy.
  3. Credential access — LSASS memory access by non-system processes; ntds.dit staging in unusual directories.
  4. Lateral movement bursts — single accounts authenticating to 5+ hosts per hour (see KQL above); PsExec service installs on servers that never receive software deployments.
  5. Data staging — large outbound transfers to consumer cloud storage (MEGA, Dropbox); rclone execution; multi-GB archives (.zip, .7z, .rar) appearing on file servers.
  6. Pre-detonation signalsvssadmin delete shadows, bcdedit ... recoveryenabled no, backup catalog deletion, AV/EDR tampering or uninstall attempts.

Critical Assets N0N Prioritizes for Exfiltration

Based on current victimology, assume targeting of:

  • Financial & payment data — transaction records, payment processor integrations (Transcom/PayPal victim pattern)
  • HR and identity data — employee PII, union membership records (UFT victim pattern)
  • Student / education records — minors' data carries extreme regulatory and reputational weight (Ministry of Education AR, BeLi Teacher)
  • Patient and clinical data — pharmaceutical and healthcare victims (AstraZeneca TR)
  • Legal & deal documents — investment agreements, M&A material (Argentem Creek, STOKR, Konnatus)
  • Customer databases & e-commerce backends — order histories, stored credentials (Fanatics, FinSoft)

Containment Actions — Ordered by Urgency

  1. Isolate, don't power off — network-quarantine affected hosts to preserve memory artifacts; N0N loaders often reside in memory.
  2. Kill the management plane — disable VPN concentrator access, rotate all edge-device credentials, revoke active sessions on Check Point/Cisco FMC.
  3. Credential reset at scale — domain admin, service accounts, and any account showing lateral burst activity. Assume KRBTGT compromise if ntds.dit was touched.
  4. Block exfil egress — emergency firewall rules denying outbound to consumer cloud storage and known RMM broker domains.
  5. Protect backups — take backup infrastructure offline or air-gap it immediately; verify immutable copies exist before any recovery planning.
  6. Engage IR retainers and counsel early — double extortion means the legal/regulatory clock (GDPR, LGPD, state breach laws) starts at exfiltration, not at encryption.

Hardening Recommendations

Immediate (24 Hours)

  • Patch the five KEV CVEs — CVE-2026-59310 (vCenter), CVE-2026-20316 (Cisco FMC), CVE-2026-50751 (Check Point IKEv1), CVE-2026-48027 (Nx Console), CVE-2024-1708 (ScreenConnect). These are confirmed ransomware entry vectors. If patching is impossible, take the management interface off the internet entirely.
  • Disable or VPN-gate RDP — no port 3389 exposure to the public internet; enforce NLA and MFA.
  • Enforce phishing-resistant MFA on all remote access, VPN, and edge-device logins.
  • Deploy the Sigma rules above into your SIEM and validate alerting on vssadmin delete shadows and unsanctioned RMM execution.
  • Block macro execution from internet-sourced Office documents (Mark-of-the-Web policies).
  • Audit RMM inventory — anything remote-access installed that IT didn't approve is an incident until proven otherwise.

Short-Term (2 Weeks)

  • Segment the virtualization layer — vCenter management interfaces on an isolated, jump-host-only network; ESXi hosts never domain-joined; separate credentials for virtualization administration.
  • Implement egress filtering — deny outbound consumer cloud storage, restrict outbound traffic to business-required destinations.
  • Deploy application allowlisting on servers to block unauthorized binaries (rclone, PsExec, ngrok).
  • Immutable, offline backups — 3-2-1 with at least one air-gapped or object-locked copy; test restoration quarterly.
  • Tier-0 credential hygiene — separate admin accounts for domain, virtualization, and backup tiers; no reuse, no interactive logon of DA accounts on member servers.
  • Tabletop the double-extortion scenario — legal, comms, and executive stakeholders must rehearse the "data is already stolen" decision tree before it happens.

Analyst Assessment

N0N's September surge is not a one-off. The batch publication pattern, financial-services weighting, and deliberate targeting of BPO/software intermediaries indicate an operation with structured affiliate management and a mature extortion pipeline. The correlation between victim geography and edge-device CVE exposure strongly suggests vulnerability-driven initial access — meaning any unpatched vCenter, Check Point gateway, Cisco FMC, or ScreenConnect instance on the internet is a live target right now.

Security teams should treat the detection content in this briefing as deployable today, not aspirational. The T-minus checklist represents real time you have — N0N's 5–14 day dwell time is your window. Use it.

Security Arsenal will continue monitoring N0N's leak site infrastructure and will publish follow-on analysis if posting tempo or TTPs shift.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.