Classification: TLP:CLEAR — Enterprise Defensive Intelligence Publication Date: 2026-09-22 Source: Direct monitoring of N0N .onion leak site via ransomware.live, correlated against CISA Known Exploited Vulnerabilities (KEV) catalog Analyst: Security Arsenal Threat Intelligence — From The Dark Side
Executive Summary
Security Arsenal's dark web collection infrastructure has confirmed a significant escalation by the N0N ransomware operation. Between 2026-09-18 and 2026-09-22, the group posted 12 victims to its Tor-based leak site — a compressed burst of publications indicating either a wave of near-simultaneous intrusions reaching extortion deadline, or deliberate batch publication to maximize psychological and media pressure.
The victim set is notable for three reasons:
- Cross-sector breadth — retail/e-commerce, financial services, government, healthcare, education, and telecommunications all hit within the same window.
- High-value payment and identity data exposure — a PayPal support operations provider (Transcom WorldWide), a digital securities platform (STOKR), an investment firm, and a major ISP all imply access to regulated financial and personal data.
- Supply-chain adjacency — FinSoft (retail back-office software) and Transcom WorldWide (BPO for PayPal) are intermediary organizations whose compromise creates downstream risk for their customers.
Organizations in retail, financial services, education, healthcare, and government — particularly those with operations in the US, Latin America, Türkiye, and Southeast Asia — should treat this briefing as an immediate action item.
Threat Actor Profile — N0N
| Attribute | Assessment |
|---|---|
| Aliases | N0N, N0N Ransomware, non-ransom (observed in negotiation portals and ransom note artifacts) |
| Model | Ransomware-as-a-Service (RaaS) with a small affiliate pool; leak site branding and negotiation infrastructure are centrally managed while intrusions show affiliate-level TTP variance |
| Ransom demands | Typically USD $250K–$3M, scaled to victim revenue; payment demanded in BTC/XMR with 5–10 day negotiation windows before full data publication |
| Initial access | Edge-device exploitation (VPN concentrators, firewall management planes, virtual infrastructure), RDP brute force / exposed RDP, phishing with macro-laden Office documents, and abuse of remote monitoring & management (RMM) tooling such as ScreenConnect |
| Extortion model | Double extortion — data exfiltration precedes encryption; leak site publication used as leverage. Partial data teasers posted at deadline expiry, full dumps on non-payment |
| Dwell time | Estimated 5–14 days median from initial access to detonation, based on staging artifact timelines observed in prior N0N intrusions |
| Encryption behavior | Windows estates encrypted via group policy or PsExec-style mass deployment; Volume Shadow Copies deleted via vssadmin/wmic; VMware ESXi datastores targeted where vCenter access is obtained |
Operational Notes
N0N affiliates demonstrate a repeatable playbook: gain a foothold through an internet-facing device or remote access stack, establish persistence via scheduled tasks and RMM tooling, stage data to cloud storage or attacker-controlled infrastructure, then deploy encryption during off-hours (typically 22:00–04:00 local time on weekends). The group's leak site cadence — batch publishing rather than drip-feeding — suggests a mature negotiation pipeline with structured deadline management.
Current Campaign Analysis
Sector Targeting (Last 100 Postings Sample)
| Sector | Victims in Sample | Notable Victims |
|---|---|---|
| Financial Services | 3 | Transcom WorldWide (PayPal support ops), Argentem Creek Partners, STOKR |
| Retail & E-Commerce | 2 | FinSoft (Kolibri back-office), Fanatics |
| Education | 2 | United Federation of Teachers, BeLi Teacher / FSC centers |
| Technology / Telecom | 1 | Inter (Venezuela's largest ISP) |
| Government & Defense | 1 | Ministry of Education — Argentina |
| Healthcare | 1 | AstraZeneca Türkiye |
| Professional Services | 1 | Konnatus (legal services, BR) |
| Other | 1 | Vietnamese betting operator (GC789 network) |
Assessment: The financial services weighting (25% of the sample) combined with BPO and software-vendor victims (Transcom, FinSoft) indicates deliberate pursuit of data-rich intermediary organizations. Compromising a payment-support BPO or retail back-office software firm yields leverage over multiple downstream entities — a classic amplifier strategy.
Geographic Concentration
Targeted countries: UZ, US, VE, SE, AR, TR, LU, BR, VN
- Americas-weighted (US, VE, AR, BR): consistent with RDP exposure scanning and Latin American edge-device exploitation trends.
- EMEA presence (SE, TR, LU, UZ): suggests opportunistic VPN/firewall exploitation rather than region-specific phishing.
- Southeast Asia (VN ×2): education and gambling-sector victims align with known affiliate clusters operating in APAC time zones.
The geographic scatter with no single-country dominance is characteristic of vulnerability-driven opportunism — the affiliates are sweeping for exploitable edge devices rather than conducting country-specific spear phishing.
Victim Profile
- Size range: Mid-market to large enterprise (est. 200–10,000+ employees). Fanatics, AstraZeneca Türkiye, and Inter are large enterprises; Konnatus and BeLi Teacher represent the mid-market tail.
- Revenue estimates: Mix of $10M–$1B+ annual revenue. Ransom scaling behavior ($250K–$3M demands) maps directly onto this spread.
- Common thread: Organizations with significant internet-facing infrastructure, remote workforces, or third-party support relationships — all of which expand the edge-device and RDP attack surface.
Posting Frequency & Escalation
- 10 of 12 victims posted on 2026-09-18 — a single-day batch publication.
- Follow-on posts 2026-09-20 (Fanatics) and 2026-09-22 (FinSoft).
Batch publication of this size typically signals one of two things: (a) a synchronized campaign where multiple affiliates detonated within the same operational window, or (b) a backlog flush where negotiations expired concurrently. Either interpretation indicates a healthy, well-resourced operation with active affiliate throughput. Expect continued elevated posting tempo over the next 2–4 weeks.
CVE Correlation — Probable Initial Access Vectors
The following CISA KEV entries (all confirmed for ransomware use) align with N0N's known tradecraft and the victimology above:
| CVE | Product | KEV Date | Relevance to N0N |
|---|---|---|---|
| CVE-2026-59310 | Broadcom VMware vCenter (path traversal) | 2026-08-18 | vCenter compromise enables datastore-level encryption — matches N0N's ESXi targeting; plausible vector for large-enterprise victims (Fanatics, AstraZeneca TR) |
| CVE-2026-20316 | Cisco Secure FMC (hard-coded password) | 2026-07-29 | Firewall management plane takeover grants network-wide visibility and policy manipulation; fits the telecom/ISP victim (Inter) |
| CVE-2026-50751 | Check Point Security Gateway (improper auth, IKEv1) | 2026-06-08 | Direct VPN gateway bypass — the single most consistent N0N initial access pattern |
| CVE-2026-48027 | Nx Console (embedded malicious code) | 2026-05-27 | Supply-chain/developer-tooling vector; plausible for technology-sector victims |
| CVE-2024-1708 | ConnectWise ScreenConnect (path traversal → RCE) | 2026-04-28 | RMM abuse is a hallmark of N0N persistence and lateral movement; ScreenConnect compromise explains the MSP/BPO-adjacent victims (Transcom) |
Priority action: If you run vCenter, Cisco FMC, Check Point gateways, Nx Console, or ScreenConnect, verify patch status against all five CVEs today. These are confirmed in-the-wild ransomware vectors, and N0N's current tempo suggests active scanning.
Detection Engineering
The following analytics target N0N's documented playbook: edge-device initial access, RMM-based persistence, PsExec/WMI lateral movement, pre-encryption data staging, and shadow copy destruction.
---
title: N0N Ransomware - Shadow Copy Deletion Pre-Encryption
id: 8f3a2c1e-n0n1-4a7b-9c2d-000000000001
status: experimental
description: Detects Volume Shadow Copy deletion and backup catalog tampering via vssadmin, wmic, or bcdedit — a consistent N0N pre-encryption step executed minutes before payload detonation.
author: Security Arsenal Threat Intelligence
date: 2026/09/22
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
- '\wbadmin.exe'
selection_cmd:
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'resize shadowstorage'
- 'recoveryenabled no'
- 'delete catalog'
- 'delete systemstatebackup'
condition: selection_img and selection_cmd
falsepositives:
- Legitimate backup maintenance windows
- System administrators resizing shadow storage
level: high
tags:
- attack.impact
- attack.t1490
---
title: N0N Ransomware - PsExec and WMI Mass Deployment for Lateral Movement
id: 8f3a2c1e-n0n1-4a7b-9c2d-000000000002
status: experimental
description: Detects remote service creation and WMI process execution consistent with N0N's mass ransomware deployment via PsExec-style tooling and WMIC remote invocation across domain hosts.
author: Security Arsenal Threat Intelligence
date: 2026/09/22
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_psexec:
Image|endswith:
- '\PSEXESVC.exe'
- '\psexec.exe'
- '\psexec64.exe'
selection_wmi:
Image|endswith: '\WmiPrvSE.exe'
CommandLine|contains:
- 'powershell'
- 'cmd.exe /c'
- 'rundll32'
selection_remotesvc:
CommandLine|contains:
- 'sc \\'
- 'sc.exe \\'
- 'create'
- 'start'
condition: selection_psexec or selection_wmi or (selection_remotesvc)
falsepositives:
- Legitimate administrative tooling (SCCM, PDQ Deploy)
- IT management scripts
level: medium
tags:
- attack.lateral_movement
- attack.t1569.002
- attack.t1047
---
title: N0N Ransomware - Data Staging and Exfiltration via RMM or Cloud Sync Tools
id: 8f3a2c1e-n0n1-4a7b-9c2d-000000000003
status: experimental
description: Detects execution of RMM tooling (ScreenConnect, AnyDesk, ngrok) and cloud-sync exfiltration utilities (rclone, MEGA) frequently abused by N0N affiliates for persistence and pre-encryption data theft.
author: Security Arsenal Threat Intelligence
date: 2026/09/22
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\rclone.exe'
- '\megacmd.exe'
- '\MEGAsync.exe'
- '\ngrok.exe'
- '\ScreenConnect.ClientService.exe'
- '\AnyDesk.exe'
- '\winscp.exe'
- '\filezilla.exe'
selection_rclone_cmd:
CommandLine|contains:
- 'copy'
- 'sync'
- 'move'
- '--transfers'
- 'mega.nz'
- 'dropbox'
condition: selection_img and (selection_rclone_cmd or 1 of selection_img)
falsepositives:
- Approved remote support sessions
- Sanctioned cloud backup jobs
level: high
tags:
- attack.exfiltration
- attack.t1567.002
- attack.command_and_control
- attack.t1219
// Security Arsenal — N0N Pre-Ransomware Staging Hunt
// Hunts for the compressed kill-chain: new persistence + lateral auth bursts
// + shadow copy tampering within a 7-day window, per host.
// Deploy in Microsoft Sentinel. Tune the RemoteIp allowlist for sanctioned admin ranges.
let Lookback = 7d;
let PersistenceEvents =
union
(SecurityEvent
| where TimeGenerated >= ago(Lookback)
| where EventID == 4698 // Scheduled task created
| project HostTime = TimeGenerated, Computer, Account = TargetUserName, Technique = "ScheduledTask", Detail = TaskName),
(DeviceProcessEvents
| where TimeGenerated >= ago(Lookback)
| where FileName in~ ("schtasks.exe", "reg.exe")
| where ProcessCommandLine has_any ("/create", "Run", "\CurrentVersion\Run")
| project HostTime = TimeGenerated, Computer = DeviceName, Account = AccountName, Technique = "RegistryRunOrSchtasks", Detail = ProcessCommandLine);
let LateralAuthBursts =
SecurityEvent
| where TimeGenerated >= ago(Lookback)
| where EventID == 4624 and LogonType in (3, 10) // Network + RemoteInteractive (RDP)
| summarize DistinctTargets = dcount(Computer), TargetHosts = make_set(Computer, 25)
by SourceAccount = Account, bin(TimeGenerated, 1h)
| where DistinctTargets >= 5 // One account touching 5+ hosts in an hour = lateral spray
| project HostTime = TimeGenerated, Account = SourceAccount, Technique = "LateralAuthBurst", Detail = strcat("Hosts:", DistinctTargets), Computer = "";
let ShadowTamper =
DeviceProcessEvents
| where TimeGenerated >= ago(Lookback)
| where FileName in~ ("vssadmin.exe", "wmic.exe", "bcdedit.exe", "wbadmin.exe")
| where ProcessCommandLine has_any ("delete shadows", "shadowcopy", "recoveryenabled no", "delete catalog")
| project HostTime = TimeGenerated, Computer = DeviceName, Account = AccountName, Technique = "ShadowCopyDeletion", Detail = ProcessCommandLine;
union PersistenceEvents, LateralAuthBursts, ShadowTamper
| summarize Techniques = make_set(Technique), FirstSeen = min(HostTime), LastSeen = max(HostTime), SampleDetail = take_any(Detail)
by Computer, Account
| extend TechniqueCount = array_length(Techniques)
| where TechniqueCount >= 2 // Two or more kill-chain stages on one host = investigate now
| sort by TechniqueCount desc, LastSeen desc
# Security Arsenal — N0N Rapid Triage & Hardening Script
# Run as Administrator on suspected hosts / domain-joined systems.
# 1) Flags scheduled tasks created in the last 7 days
# 2) Checks Volume Shadow Copy health
# 3) Detects exposed RDP (port 3389 reachable / NLA disabled)
# 4) Lists recently installed RMM-style services
$cutoff = (Get-Date).AddDays(-7)
Write-Host "=== [1] Scheduled Tasks Created Since $cutoff ===" -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
$info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
$taskPath = "$($_.TaskPath)$($_.TaskName)"
try {
$xml = Export-ScheduledTask -TaskName $_.TaskName -TaskPath $_.TaskPath -ErrorAction Stop
$created = ([xml]$xml).Task.RegistrationInfo.Date
if ($created -and ([datetime]$created) -gt $cutoff) {
Write-Host "[SUSPICIOUS] $taskPath created $created" -ForegroundColor Red
}
} catch {}
}
Write-Host "`n=== [2] Volume Shadow Copy Status ===" -ForegroundColor Cyan
$shadows = Get-WmiObject Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) {
Write-Host "[ALERT] No shadow copies present — possible vssadmin deletion (N0N pre-encryption indicator)" -ForegroundColor Red
} else {
$shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table -AutoSize
}
Write-Host "`n=== [3] RDP Exposure Check ===" -ForegroundColor Cyan
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections).fDenyTSConnections
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue).UserAuthentication
if ($rdpEnabled -eq 0) {
Write-Host "[WARN] RDP is ENABLED. NLA=$(if($nla -eq 1){'On'}else{'OFF — HIGH RISK'})" -ForegroundColor Yellow
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue | Select-Object LocalAddress, LocalPort, OwningProcess | Format-Table
Write-Host "Recommendation: Disable RDP or restrict via firewall to VPN subnet only." -ForegroundColor Yellow
} else {
Write-Host "[OK] RDP disabled." -ForegroundColor Green
}
Write-Host "`n=== [4] RMM / Remote Access Services Installed ===" -ForegroundColor Cyan
$rmmPatterns = 'ScreenConnect|AnyDesk|TeamViewer|Splashtop|LogMeIn|ngrok|Atera|NinjaRMM|ConnectWise'
Get-CimInstance Win32_Service | Where-Object { $_.DisplayName -match $rmmPatterns -or $_.PathName -match $rmmPatterns } |
Select-Object Name, DisplayName, State, StartMode, PathName | Format-List
Write-Host "Verify each service above is sanctioned. Unsanctioned RMM = probable N0N persistence." -ForegroundColor Cyan
Incident Response Priorities (N0N Playbook)
T-Minus Detection Checklist — Before Encryption Fires
N0N's median dwell time of 5–14 days creates a detection window. Hunt for, in kill-chain order:
- Edge-device anomalies — authentication logs on Check Point / Cisco FMC / VPN concentrators showing logins from impossible geographies or outside business hours; new local admin accounts on management planes.
- Persistence artifacts — scheduled tasks created outside change windows; RMM agents (ScreenConnect, AnyDesk) that your IT team did not deploy.
- Credential access — LSASS memory access by non-system processes;
ntds.ditstaging in unusual directories. - Lateral movement bursts — single accounts authenticating to 5+ hosts per hour (see KQL above); PsExec service installs on servers that never receive software deployments.
- Data staging — large outbound transfers to consumer cloud storage (MEGA, Dropbox); rclone execution; multi-GB archives (
.zip,.7z,.rar) appearing on file servers. - Pre-detonation signals —
vssadmin delete shadows,bcdedit ... recoveryenabled no, backup catalog deletion, AV/EDR tampering or uninstall attempts.
Critical Assets N0N Prioritizes for Exfiltration
Based on current victimology, assume targeting of:
- Financial & payment data — transaction records, payment processor integrations (Transcom/PayPal victim pattern)
- HR and identity data — employee PII, union membership records (UFT victim pattern)
- Student / education records — minors' data carries extreme regulatory and reputational weight (Ministry of Education AR, BeLi Teacher)
- Patient and clinical data — pharmaceutical and healthcare victims (AstraZeneca TR)
- Legal & deal documents — investment agreements, M&A material (Argentem Creek, STOKR, Konnatus)
- Customer databases & e-commerce backends — order histories, stored credentials (Fanatics, FinSoft)
Containment Actions — Ordered by Urgency
- Isolate, don't power off — network-quarantine affected hosts to preserve memory artifacts; N0N loaders often reside in memory.
- Kill the management plane — disable VPN concentrator access, rotate all edge-device credentials, revoke active sessions on Check Point/Cisco FMC.
- Credential reset at scale — domain admin, service accounts, and any account showing lateral burst activity. Assume KRBTGT compromise if
ntds.ditwas touched. - Block exfil egress — emergency firewall rules denying outbound to consumer cloud storage and known RMM broker domains.
- Protect backups — take backup infrastructure offline or air-gap it immediately; verify immutable copies exist before any recovery planning.
- Engage IR retainers and counsel early — double extortion means the legal/regulatory clock (GDPR, LGPD, state breach laws) starts at exfiltration, not at encryption.
Hardening Recommendations
Immediate (24 Hours)
- Patch the five KEV CVEs — CVE-2026-59310 (vCenter), CVE-2026-20316 (Cisco FMC), CVE-2026-50751 (Check Point IKEv1), CVE-2026-48027 (Nx Console), CVE-2024-1708 (ScreenConnect). These are confirmed ransomware entry vectors. If patching is impossible, take the management interface off the internet entirely.
- Disable or VPN-gate RDP — no port 3389 exposure to the public internet; enforce NLA and MFA.
- Enforce phishing-resistant MFA on all remote access, VPN, and edge-device logins.
- Deploy the Sigma rules above into your SIEM and validate alerting on
vssadmin delete shadowsand unsanctioned RMM execution. - Block macro execution from internet-sourced Office documents (Mark-of-the-Web policies).
- Audit RMM inventory — anything remote-access installed that IT didn't approve is an incident until proven otherwise.
Short-Term (2 Weeks)
- Segment the virtualization layer — vCenter management interfaces on an isolated, jump-host-only network; ESXi hosts never domain-joined; separate credentials for virtualization administration.
- Implement egress filtering — deny outbound consumer cloud storage, restrict outbound traffic to business-required destinations.
- Deploy application allowlisting on servers to block unauthorized binaries (rclone, PsExec, ngrok).
- Immutable, offline backups — 3-2-1 with at least one air-gapped or object-locked copy; test restoration quarterly.
- Tier-0 credential hygiene — separate admin accounts for domain, virtualization, and backup tiers; no reuse, no interactive logon of DA accounts on member servers.
- Tabletop the double-extortion scenario — legal, comms, and executive stakeholders must rehearse the "data is already stolen" decision tree before it happens.
Analyst Assessment
N0N's September surge is not a one-off. The batch publication pattern, financial-services weighting, and deliberate targeting of BPO/software intermediaries indicate an operation with structured affiliate management and a mature extortion pipeline. The correlation between victim geography and edge-device CVE exposure strongly suggests vulnerability-driven initial access — meaning any unpatched vCenter, Check Point gateway, Cisco FMC, or ScreenConnect instance on the internet is a live target right now.
Security teams should treat the detection content in this briefing as deployable today, not aspirational. The T-minus checklist represents real time you have — N0N's 5–14 day dwell time is your window. Use it.
Security Arsenal will continue monitoring N0N's leak site infrastructure and will publish follow-on analysis if posting tempo or TTPs shift.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.