Classification: TLP:CLEAR | Publication Date: 2026-09-23 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
Executive Summary
Dark web monitoring of the ransomware group N0N's leak site, conducted via ransomware.live, shows 13 new victim listings published between 2026-09-18 and 2026-09-22. The claimed victims span eight countries (ML, UZ, US, VE, SE, AR, TR, LU — with additional listings referencing BR and VN in victim descriptors) and at least eight sectors, including Technology, Retail & E-Commerce, Financial Services, Government & Defense, Healthcare, Professional Services, and Education.
Every listing in this batch is single-source — observed on one crawler feed only, with no independent second-crawler confirmation that the postings exist at all, let alone that the underlying claims are true. We assess the posting cluster as noteworthy for its breadth and velocity (11 of 13 listings published on a single day, 2026-09-18), a pattern consistent with a gang attempting to inflate its public profile. Enterprise defenders in the named sectors should treat this as a prompt to validate exposure — not as confirmation that any specific organization has been compromised.
Sourcing & Verification
- Corroboration status: 0 of 13 listings were independently observed by a second leak-site crawler; all 13 appear on a single source (ransomware.live) only. Single-source status does not mean the claim is false — it means we cannot currently verify the posting itself was independently observed.
- What inclusion means: Each organization below is included solely because the N0N ransomware group claims to have compromised it. Inclusion is not confirmation of a breach. A leak-site posting is an accusation by a criminal actor and may be exaggerated, fabricated, recycled, or refer to a third party's data rather than the named organization's own systems.
- Disputes and denials: A named organization may dispute a listing. Conversely, a denial is not proof the claim is false, and silence is not proof it is true — disclosure obligations vary by jurisdiction and not every incident is reportable. Neither silence nor denial settles the question; only the organization or its regulator can confirm an incident.
- Corrections: Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — N0N
| Attribute | Assessment |
|---|---|
| Aliases | No widely adopted alternate aliases are publicly tracked; the brand appears as "N0N" (zero in place of the letter O) on its .onion leak infrastructure |
| Operating model | Assessed as a closed or semi-closed operation; the sudden, high-volume posting pattern (11 listings in one day) is atypical of mature RaaS programs with steady affiliate throughput and may indicate a newer or rebranding operation seeking visibility |
| Ransom demands | Not publicly standardized at this time; demand sizing in comparable emerging groups typically ranges from low six figures to low seven figures USD, scaled to claimed victim revenue |
| Initial access methods | Emerging groups of this profile most commonly rely on: (1) exploitation of exposed edge devices (VPN concentrators, firewalls), (2) phishing with macro- or script-laden attachments, (3) brute-forced or purchased RDP credentials, and (4) access purchased from initial access brokers. These are sector-level hypotheses, not confirmed vectors for any listing below |
| Extortion model | Double extortion — data theft threatened alongside encryption, per the leak-site posting model itself |
| Dwell time | No gang-specific dwell-time telemetry exists in our collection. Sector baselines for comparable groups run 5–14 days from initial access to detonation |
Analyst note: The diversity of the listing set — spanning Mali, Uzbekistan, Venezuela, Argentina, Türkiye, Luxembourg, and Vietnam alongside the US and Sweden — combined with zero multi-source corroboration raises the possibility that some listings are opportunistic, recycled from prior incidents, or reference third-party/supply-chain relationships (e.g., one listing references "PayPal support operations" via a BPO provider rather than PayPal itself). Treat every claim with heightened skepticism.
Current Campaign Analysis
Claimed Victim Listings (2026-09-18 to 2026-09-22)
N0N has listed the following organizations on its dark web leak site. All are single-source, unverified claims:
| Organization (as listed) | Sector | Country | Published |
|---|---|---|---|
| AFRICA-TECH (IT services / document processing) | Technology | ML | 2026-09-22 |
| FinSoft (Kolibri retail back-office software) | Retail & E-Commerce | UZ | 2026-09-22 |
| Fanatics (global sports commerce platform) | Retail & E-Commerce | US | 2026-09-20 |
| Inter (Venezuela's largest internet provider) | Technology | VE | 2026-09-18 |
| PayPal support operations (Transcom WorldWide) | Financial Services | SE | 2026-09-18 |
| Ministry of Education — Argentina | Government & Defense | AR | 2026-09-18 |
| Argentem Creek Partners (investment firm) | Financial Services | US | 2026-09-18 |
| AstraZeneca Türkiye | Healthcare | TR | 2026-09-18 |
| STOKR (digital securities platform) | Financial Services | LU | 2026-09-18 |
| Konnatus (usucapião legal services) | Professional Services | BR | 2026-09-18 |
| BeLi Teacher / FSC education centers (AWS) | Education | VN | 2026-09-18 |
| Vietnamese betting operator (GC789 network / Boundless TE) | Other | VN | 2026-09-18 |
| United Federation of Teachers | Education | US | 2026-09-18 |
Sector Targeting
Financial Services is the heaviest claimed sector (3 listings), followed by Technology, Retail & E-Commerce, and Education (2 each). The mix of high-value targets (an investment firm, a digital securities platform, a payments-adjacent BPO) with softer targets (education centers, a betting operator, niche legal services) is characteristic of opportunistic access-driven victimology rather than deliberate sector campaigns.
Geographic Concentration
No single-country concentration. Latin America accounts for 4 of 13 listings (VE, AR, BR descriptor), the US for 3, with the remainder scattered across West Africa, Central Asia, the Nordics, Türkiye, and Southeast Asia. This dispersion reinforces the opportunistic-access hypothesis — the gang appears to monetize whatever access it obtains rather than prosecuting a regional campaign.
Victim Profile
The set spans global enterprises (a major sports commerce platform, a multinational pharma subsidiary), mid-market firms (an investment firm, a digital securities platform, an ISP), and small/niche entities (a legal services boutique, regional education centers). Implied revenue range spans from sub-$10M SMBs to multi-billion-dollar enterprises — again consistent with access-broker-driven, non-selective victimology.
Posting Cadence & Escalation
The pattern is a burst, not a drip: 11 listings on 2026-09-18, one on 2026-09-20, two on 2026-09-22. Burst posting is frequently used by emerging gangs to simulate operational scale and pressure multiple victims simultaneously with public-shaming deadlines. Watch for: (a) sample-data publication as the next escalation step, (b) listings quietly removed (indicating either payment or claim collapse), and (c) whether any second crawler begins corroborating the site's content.
CVE Exposure Hypothesis (Sector-Level — NOT Victim Attribution)
We have no evidence linking any CVE to any specific listing above. However, the following CISA KEV entries represent edge and management-plane exposure that ransomware operators broadly — including groups with N0N's profile — are known to exploit. Organizations in the named sectors should validate patching regardless of whether they appear in this data:
- CVE-2026-59310 (Broadcom VMware vCenter path traversal, KEV 2026-08-18) — hypervisor management plane; high-value target for pre-encryption mass compromise of virtualized estates.
- CVE-2026-20316 (Cisco Secure FMC hard-coded password, KEV 2026-07-29) — network security management plane; enables persistent foothold on perimeter infrastructure.
- CVE-2026-50751 (Check Point Security Gateway improper authentication in IKEv1, KEV 2026-06-08) — VPN edge; a classic ransomware initial-access surface.
- CVE-2026-48027 (Nx Console embedded malicious code, KEV 2026-05-27) — developer toolchain supply-chain exposure; relevant to technology-sector targets.
- CVE-2024-1708 (ConnectWise ScreenConnect path traversal, KEV 2026-04-28) — RMM tooling; heavily abused by ransomware actors for initial access and lateral movement via managed service channels.
Detection Engineering
The following detections target the TTP cluster associated with N0N's profile: edge/VPN exploitation, phishing-driven macro execution, RDP brute force, PsExec/WMI lateral movement, Cobalt Strike-style beaconing, and pre-encryption data staging.
---
title: Suspicious Office Macro Spawning Script or LOLBin Child Process
description: Detects Microsoft Office applications spawning script interpreters or living-off-the-land binaries, consistent with phishing-macro initial access used by ransomware groups of N0N's profile.
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\cmd.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate Office add-ins invoking system utilities
level: high
tags:
- attack.initial_access
- attack.t1566.001
- attack.t1059
status: experimental
author: Security Arsenal Threat Intelligence
reference: https://securityarsenal.com/darkside
date: 2026/09/23
---
title: PsExec or Remote Service Creation Followed by WMI Activity
description: Detects remote service installation (PsExec-style) and WMI process execution indicative of ransomware lateral movement prior to mass encryption.
logsource:
category: process_creation
product: windows
detection:
selection_psexec:
Image|endswith:
- '\psexec.exe'
- '\psexesvc.exe'
- '\paexec.exe'
- '\csexec.exe'
selection_wmi:
ParentImage|endswith: '\wmiprvse.exe'
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\vssadmin.exe'
- '\bcdedit.exe'
- '\wmic.exe'
condition: 1 of selection_*
falsepositives:
- Legitimate administrative tooling (SCCM, PDQ, management agents) — baseline admin hosts before tuning
level: high
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1047
- attack.t1569.002
status: experimental
author: Security Arsenal Threat Intelligence
reference: https://securityarsenal.com/darkside
date: 2026/09/23
---
title: Pre-Ransomware Data Staging and Shadow Copy Tampering
description: Detects Volume Shadow Copy deletion, boot configuration tampering, and archive-tool execution on servers — the classic T-minus staging sequence before ransomware detonation.
logsource:
category: process_creation
product: windows
detection:
selection_vss:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'recoveryenabled no'
- 'ignoreallfailures'
selection_staging:
Image|endswith:
- '\rar.exe'
- '\7z.exe'
- '\winrar.exe'
CommandLine|contains:
- ' a '
- ' -p'
condition: 1 of selection_*
falsepositives:
- Backup administrators performing maintenance; scheduled archival jobs
level: critical
tags:
- attack.impact
- attack.t1490
- attack.t1560.001
status: experimental
author: Security Arsenal Threat Intelligence
reference: https://securityarsenal.com/darkside
date: 2026/09/23
The following Microsoft Sentinel hunt query identifies the lateral-movement and pre-staging sequence: anomalous remote logons (RDP/SMB) followed within a short window by service creation, WMI execution, or shadow-copy tampering on the same host.
// N0N-profile hunt: remote logon -> lateral tool -> staging/impact sequence
let lookback = 7d;
let staging_window = 4h;
let RemoteLogons =
SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4624 and LogonType in (3, 10)
| where IpAddress !startswith "10." or IpAddress == "-" // tune: flag unexpected sources
| summarize FirstLogon = min(TimeGenerated), Sources = make_set(Account) by Computer, IpAddress;
let LateralAndStaging =
union
(SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 7045 // new service installed (PsExec-style)
| extend Indicator = strcat("ServiceInstall: ", ServiceName), Host = Computer),
(DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where (InitiatingProcessFileName =~ "wmiprvse.exe" and FileName in~ ("cmd.exe","powershell.exe","vssadmin.exe","bcdedit.exe"))
or (ProcessCommandLine has_any ("delete shadows","shadowcopy delete","recoveryenabled no","ignoreallfailures"))
or (FileName in~ ("rar.exe","7z.exe") and ProcessCommandLine has " -p")
| extend Indicator = strcat(FileName, " | ", ProcessCommandLine), Host = DeviceName));
LateralAndStaging
| join kind=inner RemoteLogons on $left.Host == $right.Computer
| where TimeGenerated between (FirstLogon .. (FirstLogon + staging_window))
| summarize Indicators = make_set(Indicator), FirstSeen = min(TimeGenerated), SourceIPs = make_set(IpAddress)
by Host
| where array_length(Indicators) >= 1
| order by FirstSeen asc;
The following rapid-response script enumerates three of the highest-signal pre-detonation artifacts: scheduled tasks created in the last 7 days (persistence), shadow copy inventory status (anti-recovery tampering), and exposed RDP listeners with recent failed-logon pressure (brute force).
# Security Arsenal - Rapid Triage: N0N-profile pre-ransomware indicators
# Run elevated. Review output before taking action.
$report = @()
Write-Host "[*] Scheduled tasks created in the last 7 days..." -ForegroundColor Cyan
$tasks = Get-ScheduledTask | ForEach-Object {
$info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
[PSCustomObject]@{
TaskName = $_.TaskName
TaskPath = $_.TaskPath
Author = $_.Author
Date = $_.Date
State = $_.State
ActionExe = ($_.Actions | ForEach-Object { $_.Execute }) -join '; '
}
} | Where-Object { $_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7) }
$report += "=== NEW SCHEDULED TASKS (7d) ===`n" + ($tasks | Format-Table -AutoSize | Out-String)
Write-Host "[*] Volume Shadow Copy status..." -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
$report += "=== SHADOW COPIES ===`n" +
($(if ($shadows) { $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table -AutoSize | Out-String }
else { "`n*** WARNING: NO SHADOW COPIES PRESENT - possible anti-recovery tampering ***`n" }))
$vss = Get-Service VSS
$report += "VSS Service Status: $($vss.Status) / StartType: $($vss.StartType)`n"
Write-Host "[*] RDP exposure and failed-logon pressure..." -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
$report += "=== RDP LISTENER ===`n" +
($(if ($rdp) { "RDP LISTENING on 3389 - verify it is not internet-exposed`n" } else { "No RDP listener`n" }))
$fails = Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} -MaxEvents 2000 -ErrorAction SilentlyContinue |
Where-Object { $_.Message -match 'Logon Type:\s+(3|10)' } |
Group-Object { ([regex]::Match($_.Message, 'Source Network Address:\s+(\S+)')).Groups[1].Value } |
Sort-Object Count -Descending | Select-Object -First 10
$report += "=== TOP FAILED RDP/SMB LOGON SOURCES (24h) ===`n" + ($fails | Format-Table Count, Name -AutoSize | Out-String)
$out = "N0N_RapidTriage_$(Get-Date -Format 'yyyyMMdd_HHmm').txt"
$report | Out-File $out
Write-Host "[+] Report written to $out — escalate any shadow-copy gaps or unfamiliar tasks to IR immediately." -ForegroundColor Green
Incident Response Priorities
T-Minus Detection Checklist (Before Encryption Fires)
- New scheduled tasks or services on servers, especially executing from
%TEMP%,%ProgramData%, or user profile paths -
vssadmin delete shadows,bcdedit ... recoveryenabled no, orwmic shadowcopy deleteexecution anywhere in the estate - PsExec-style service installs (
PSEXESVC, random 8-character service names) across multiple hosts within a short window - Archive tooling (RAR/7-Zip) running against file shares, databases, or document repositories — particularly with password switches
- Egress spikes to unfamiliar cloud storage, MEGA/paste-style sites, or VPS IPs from servers that do not normally transfer bulk data
- Authentication anomalies on VPN concentrators, firewalls, and FMC/management planes — new admin accounts, logons from unusual geographies, or IKEv1 negotiation anomalies (relevant to CVE-2026-50751 exposure)
- EDR tampering: sensors disabled, exclusions added, or security services stopped
Assets This Profile Historically Prioritizes for Exfiltration
Based on the double-extortion model and the sectors claimed in this batch, prioritize protection and egress monitoring around:
- Financial data stores — transaction records, portfolio/client data (investment and securities-firm relevance)
- Identity and HR repositories — payroll, member records (union and education-sector relevance)
- Customer PII and payment-adjacent data — support ticket systems, CRM exports (BPO/retail relevance)
- Legal and case files — document management systems (professional services relevance)
- Network diagrams, credentials, and backups — anything that increases extortion leverage or enables re-entry
Containment Actions Ordered by Urgency
- Isolate at the network layer first — VLAN/segment isolation of affected hosts; do NOT power off (preserves volatile evidence and memory-resident key material).
- Disable suspected compromised accounts and revoke sessions/tokens, including VPN, SSO, and service accounts.
- Block egress at the perimeter to known exfil destinations; sinkhole or deny uncategorized cloud storage.
- Preserve forensic evidence — memory captures and disk images of the first-detected host before any remediation.
- Verify backup integrity and offline status before declaring recovery; assume the actor enumerated backup infrastructure.
- Reset KRBTGT twice and rotate all domain-admin credentials if domain-level compromise is suspected.
- Engage IR retainer and legal counsel early — extortion deadlines are short, and regulatory clocks (where applicable) start at confirmation, not at the leak posting.
Hardening Recommendations
Immediate (24 hours)
- Patch or mitigate the KEV-listed edge exposure: Validate remediation of CVE-2026-59310 (vCenter), CVE-2026-20316 (Cisco FMC), and CVE-2026-50751 (Check Point IKEv1) on all internet-facing management planes. Where patching is not immediately possible, restrict management interfaces to allow-listed admin networks.
- Audit RDP exposure: Confirm no direct internet-facing RDP; enforce VPN + MFA in front of any remote administration. Review the last 30 days of type-3/type-10 logons for anomalies.
- Block macro execution from the internet zone (Mark-of-the-Web enforcement) and restrict Office child-process creation per the Sigma rule above.
- Deploy the shadow-copy and staging detections from this briefing; alert (do not just log) on
vssadmin delete shadowsand password-protected archive creation on servers. - Verify MFA on all remote access and privileged accounts, including service-provider/BPO connectivity into your environment — the claimed BPO-adjacent listing underscores third-party access risk.
Short-Term (2 weeks)
- Segment critical data stores from general user VLANs; require separate, vaulted credentials for backup infrastructure and make at least one backup tier immutable or offline.
- Deploy egress filtering and DLP-aware alerting on bulk outbound transfers from servers; ransomware economics depend on exfiltration succeeding before detonation.
- Establish third-party/BPO access governance: time-bound credentials, conditional access, and monitoring on any vendor with support-desk or back-office reach into your systems.
- Adopt attack-surface management to continuously enumerate exposed VPN, firewall management, and RMM (ScreenConnect-class) interfaces — the access classes most plausibly feeding campaigns of this profile.
- Tabletop the extortion scenario — not just the encryption scenario — so legal, comms, and executives know decision authority before a leak-site countdown timer is running.
All victim references in this briefing reflect unverified claims published on N0N's dark web leak site and observed via a single monitoring source. No organization named here has been confirmed breached by Security Arsenal. Named organizations are invited to contact security@securityarsenal.com.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.