Classification: TLP:CLEAR | Publication Date: 2026-09-23 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
N0N Ransomware Gang: 13 New Leak-Site Listings in 6 Days
Executive Summary
Between 2026-09-18 and 2026-09-22, the ransomware group tracked as N0N published 13 new victim listings on its dark web leak site, according to monitoring of the gang's .onion infrastructure via ransomware.live. The claimed victims span eight sectors — Technology, Retail & E-Commerce, Financial Services, Government & Defense, Healthcare, Professional Services, Education, and Other — across eight countries: Mali (ML), Uzbekistan (UZ), United States (US), Venezuela (VE), Sweden (SE), Argentina (AR), Türkiye (TR), and Luxembourg (LU), with additional listings referencing Brazil and Vietnam-based operations.
Every listing in this dataset is an accusation by a criminal actor. None of the 13 postings constitutes a confirmed breach, and none has been corroborated by a second independent leak-site crawler. Security teams at organizations in the named sectors — and at the named organizations themselves — should treat this as a prompt to validate detection coverage against N0N-aligned tradecraft, not as confirmation that any specific incident occurred.
Key observations:
- Posting velocity: 11 of 13 listings appeared on a single day (2026-09-18), suggesting a batch-release pattern consistent with either a backlog dump or a pressure tactic against multiple alleged victims simultaneously.
- Notable claimed names: Fanatics (global sports commerce), PayPal support operations via Transcom WorldWide, AstraZeneca Türkiye, the Ministry of Education of Argentina, and the United Federation of Teachers — a mix of direct enterprises and third-party/service-provider targets.
- Supply-chain flavor: Several listings (Inter — an ISP; Transcom — a BPO provider; AFRICA-TECH — IT services) suggest N0N may be pursuing victims whose compromise could cascade to downstream customers, a hallmark of modern double-extortion economics.
Sourcing & Verification
This briefing is built from leak-site monitoring data, and the provenance matters:
- Corroboration status: 0 of 13 listings were independently observed by a second leak-site crawler. 13 of 13 appear on a single source only (ransomware.live's crawl of the gang's onion site). Single-source means no second crawler has confirmed the posting even exists on the gang's site.
- Inclusion reflects the threat actor's claim — it is NOT confirmation of a breach. No corroboration tier in this data confirms that any organization was compromised. Only the named organization or its regulator can confirm that.
- A named organization may dispute a listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question; ransomware gangs are also known to exaggerate, misattribute, or fabricate claims.
- Corrections: Security Arsenal will publish corrections to this briefing if any claim is resolved or retracted. We welcome contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — N0N
Attribution caveat: Public reporting on N0N is limited relative to established brands (LockBit, ALPHV, Akira). The profile below combines what is observable from the gang's leak-site behavior with tradecraft patterns consistent with its operating tier. Items marked (hypothesis) are analytical judgment, not confirmed fact.
- Aliases: No widely documented aliases at time of publication. The group brands itself as "N0N" on its onion leak site.
- Operating model: (Hypothesis) The victim breadth (8 sectors, 8 countries, no discernible vertical focus) is more consistent with an opportunistic RaaS affiliate model or an affiliate-driven closed group than a tightly scoped targeted operation. Closed groups typically show sector or regional discipline; N0N shows none.
- Ransom demands: No verified demand amounts are public. Groups at this maturity tier typically calibrate demands to victim revenue, ranging from low five figures for SMBs to seven figures for enterprises (hypothesis based on comparable actors).
- Double extortion: Confirmed by behavior — the gang operates a public leak site and names victims, which is itself the extortion mechanism: data-theft-threat-first, encryption optional. Modern affiliates increasingly skip encryption entirely if exfiltration pressure suffices.
- Initial access methods (sector-level hypothesis, not tied to any named victim): Groups with N0N's opportunistic victimology most commonly gain entry via:
- Exploitation of internet-facing edge devices and virtualization infrastructure (VPN concentrators, firewalls, vCenter) — see the KEV overlap below.
- Purchased access from initial access brokers (IABs) selling RDP/VPN credentials.
- Phishing with macro-enabled documents or HTML smuggling loaders.
- Dwell time: (Hypothesis) Batch posting of 11 victims on one day suggests the gang sits on access for days-to-weeks before listing, consistent with the industry-observed 3–14 day median dwell time for exfiltration-first operations.
Current Campaign Analysis
Claimed victim list (as published on N0N's leak site)
| Organization | Sector | Country | Listed | Corroboration |
|---|---|---|---|---|
| AFRICA-TECH (IT services / document processing) | Technology | ML | 2026-09-22 | Single-source |
| FinSoft (Kolibri retail back-office software) | Retail & E-Commerce | UZ | 2026-09-22 | Single-source |
| Fanatics (global sports commerce platform) | Retail & E-Commerce | US | 2026-09-20 | Single-source |
| Inter (Venezuela's largest internet provider) | Technology | VE | 2026-09-18 | Single-source |
| PayPal support operations (Transcom WorldWide) | Financial Services | SE | 2026-09-18 | Single-source |
| Ministry of Education — Argentina | Government & Defense | AR | 2026-09-18 | Single-source |
| Argentem Creek Partners (investment firm) | Financial Services | US | 2026-09-18 | Single-source |
| AstraZeneca Türkiye | Healthcare | TR | 2026-09-18 | Single-source |
| STOKR (digital securities platform) | Financial Services | LU | 2026-09-18 | Single-source |
| Konnatus (usucapião legal services) | Professional Services | BR | 2026-09-18 | Single-source |
| BeLi Teacher / FSC education centers (AWS) | Education | VN | 2026-09-18 | Single-source |
| Vietnamese betting operator (GC789 network / Boundless TE) | Other | VN | 2026-09-18 | Single-source |
| United Federation of Teachers | Education | US | 2026-09-18 | Single-source |
Sector targeting
Financial Services leads with three claimed victims (Argentem Creek Partners, STOKR, Transcom/PayPal support operations), followed by Technology, Retail & E-Commerce, and Education with two each. The education listings (a national ministry, a major teachers' union, and an ed-tech provider) fit a broader 2026 pattern of ransomware crews treating education as a soft-target vertical with weak segmentation and high extortion sensitivity.
Geographic concentration
There is no single geographic concentration — the listing set spans West Africa, Central Asia, North America, South America, Northern Europe, Türkiye, and Southeast Asia. This scatter reinforces the opportunistic-access hypothesis: the gang (or its affiliates) appears to be monetizing whatever access it acquires rather than prosecuting a deliberate regional campaign.
Victim profile
The set mixes large enterprises (Fanatics, AstraZeneca Türkiye, Inter) with mid-market firms (Argentem Creek Partners, STOKR, FinSoft) and SMBs (Konnatus, education centers). Estimated revenue range spans roughly $5M to $5B+ — the widest band we typically see from a single group in a single week, again consistent with an affiliate-driven "take what access brokers offer" model. Notably, several listings are service providers (BPO, ISP, IT services, ed-tech hosted on AWS) whose compromise — if real — would expose downstream customer data, multiplying extortion leverage.
Posting frequency / escalation pattern
- 2026-09-18: 11 listings posted in a single batch.
- 2026-09-20: 1 listing (Fanatics).
- 2026-09-22: 2 listings (AFRICA-TECH, FinSoft).
Batch drops on a Friday followed by weekend trickle is a known pressure cadence: maximize victim panic before Monday business hours, then add names to demonstrate momentum. Watch for a second wave around 2026-09-25/26 if the gang follows the typical 7-day escalation cycle before leaking data samples.
CVE exposure overlap (sector-level hypothesis — NOT linked to any named victim)
We have no evidence connecting any specific CVE to any specific named listing. However, N0N's opportunistic victimology overlaps heavily with the classes of edge and CI/CD infrastructure currently on CISA's Known Exploited Vulnerabilities list with confirmed ransomware use. Defenders should treat the following as priority patching exposure that gangs of N0N's profile are known to exploit:
- CVE-2026-59310 — VMware vCenter path traversal (KEV 2026-08-18). Hypervisor-layer compromise enables mass encryption of entire VM estates — the highest-impact ransomware outcome.
- CVE-2026-63077 — JetBrains TeamCity deserialization, unauthenticated RCE (KEV 2026-08-05). Build servers hold source code, secrets, and deployment credentials — premium exfiltration targets.
- CVE-2026-20316 — Cisco Secure FMC hard-coded password (KEV 2026-07-29). Management-plane takeover of the firewall itself blinds perimeter telemetry.
- CVE-2026-50751 — Check Point Security Gateway improper authentication in IKEv1 (KEV 2026-06-08). VPN edge devices remain the #1 ransomware entry vector.
- CVE-2026-48027 — Nx Console embedded malicious code (KEV 2026-05-27). Developer-toolchain supply chain compromise, directly relevant to the technology and software-sector names on N0N's list.
Detection Engineering
The following content targets TTPs associated with opportunistic ransomware operations of N0N's profile: edge-device/VPN initial access, macro-based phishing execution, RDP brute forcing, PsExec/WMI lateral movement, Cobalt Strike-style beaconing, and pre-encryption data staging.
---
title: Ransomware Pre-Detonation - Volume Shadow Copy Deletion via vssadmin or wmic
id: 7f3a1c2e-9n0n-4a5b-8c6d-2026n0n0001
status: experimental
description: Detects deletion or resize of Volume Shadow Copies, a near-universal pre-encryption step observed across opportunistic ransomware affiliates including groups with N0N's leak-site profile. Correlate with surrounding process ancestry before treating as benign admin activity.
author: Security Arsenal Threat Intelligence
date: 2026/09/23
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
- '\wbadmin.exe'
selection_cmd:
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'resize shadowstorage'
- 'recoveryenabled no'
- 'delete catalog'
condition: selection_img and selection_cmd
falsepositives:
- Legitimate backup administration (Veeam, Commvault maintenance windows)
- System administrators performing storage reclamation
level: high
tags:
- attack.impact
- attack.t1490
---
title: Suspicious Office Macro Spawning Script or LOLBin Child Process
id: 7f3a1c2e-9n0n-4a5b-8c6d-2026n0n0002
status: experimental
description: Detects Office applications spawning script interpreters or living-off-the-land binaries, consistent with phishing-macro initial access chains used by ransomware affiliates to deploy loaders and Cobalt Strike beacons.
author: Security Arsenal Threat Intelligence
date: 2026/09/23
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
- '\mspub.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
- '\certutil.exe'
- '\cmd.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate Office add-in automation; baseline by parent-child hash pairs
level: high
tags:
- attack.execution
- attack.t1204.002
- attack.t1059
---
title: PsExec-Style Remote Service Creation Followed by WMI or ADMIN$ Write
id: 7f3a1c2e-9n0n-4a5b-8c6d-2026n0n0003
status: experimental
description: Detects service installation events (7045) with service binary paths or names consistent with PsExec-style lateral movement (PSEXESVC, random 8-char names, ADMIN$ paths), a hallmark of ransomware operator hands-on-keyboard movement between initial access and detonation.
author: Security Arsenal Threat Intelligence
date: 2026/09/23
logsource:
product: windows
service: system
detection:
selection_event:
EventID: 7045
selection_suspicious:
Service_File_Name|contains:
- 'PSEXESVC'
- 'ADMIN$'
- '\\Users\\Public\\'
- '\\Windows\\Temp\\'
- 'paexec'
- 'csexec'
Service_Name|re: '^[A-Za-z0-9]{8}$'
condition: selection_event and selection_suspicious
falsepositives:
- Legitimate remote administration tooling (SCCM, PDQ Deploy) - allowlist by service name and signer
level: high
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1569.002
// Microsoft Sentinel — N0N-profile pre-ransomware staging hunt
// Looks for the classic kill-chain residue: mass archive creation (staging),
// shadow copy tampering, and anomalous outbound transfer volume — pivoted per host
// over a rolling 7-day window. Tune allowlists for your backup/archive tooling.
let Window = 7d;
let SuspiciousArchiveProcs = dynamic(["7z.exe","rar.exe","winrar.exe","7za.exe","7zg.exe","tar.exe","makecab.exe"]);
let ShadowCopyCmds = dynamic(["delete shadows","shadowcopy delete","resize shadowstorage","recoveryenabled no","delete catalog"]);
// 1) Archive-tool execution on servers/workstations (data staging)
let Staging =
DeviceProcessEvents
| where TimeGenerated > ago(Window)
| where FileName in~ (SuspiciousArchiveProcs)
| project StagingTime=TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, FolderPath;
// 2) Shadow copy / backup tampering (pre-encryption prep)
let Tamper =
DeviceProcessEvents
| where TimeGenerated > ago(Window)
| where ProcessCommandLine has_any (ShadowCopyCmds)
| project TamperTime=TimeGenerated, DeviceName, InitiatingProcessAccountName, ProcessCommandLine;
// 3) Abnormal outbound transfer from the same hosts (exfil before leak-site listing)
let Exfil =
DeviceNetworkEvents
| where TimeGenerated > ago(Window)
| where RemoteIPType == "Public"
| summarize BytesOut=sum(todouble(column_ifexists("SentBytes", 0))), Destinations=dcount(RemoteIP), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated)
by DeviceName, InitiatingProcessFileName
| where Destinations > 25 // fan-out to many public IPs: cloud storage / MEGA / rclone patterns
| project DeviceName, InitiatingProcessFileName, BytesOut, Destinations, FirstSeen, LastSeen;
// Join: hosts showing >= 2 of the 3 behaviors within the window are the priority queue
let StagingHosts = Staging | summarize by DeviceName;
let TamperHosts = Tamper | summarize by DeviceName;
let ExfilHosts = Exfil | summarize by DeviceName;
union (StagingHosts | evaluate bag_unpack(pack("Signal","Staging"))),
(TamperHosts | evaluate bag_unpack(pack("Signal","BackupTamper"))),
(ExfilHosts | evaluate bag_unpack(pack("Signal","ExfilFanOut")))
| summarize Signals=make_set(Signal), SignalCount=dcount(Signal) by DeviceName
| where SignalCount >= 2
| join kind=leftouter (Staging) on DeviceName
| join kind=leftouter (Tamper) on DeviceName
| order by SignalCount desc, DeviceName asc;
# Security Arsenal — Rapid Triage: N0N-Profile Pre-Ransomware Indicators
# Run on suspect hosts or fleet-wide via your RMM/EDR. Read-only; no changes made.
# Checks: exposed RDP, scheduled tasks created in last 7 days, shadow copy state,
# suspicious services (PsExec-style), and archive-tool artifacts.
$report = @()
$cutoff = (Get-Date).AddDays(-7)
# 1) Is RDP enabled and exposed?
$rdpEnabled = (Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue).fDenyTSConnections
$rdpStatus = if ($rdpEnabled -eq 0) { "ENABLED - verify it is not internet-exposed" } else { "Disabled" }
$report += [pscustomobject]@{ Check = "RDP State"; Finding = $rdpStatus; Severity = $(if ($rdpEnabled -eq 0) {"Review"} else {"OK"}) }
# 2) Scheduled tasks created in the last 7 days (persistence / detonation staging)
try {
$recentTasks = Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt $cutoff } |
Select-Object TaskName, TaskPath, Date
if ($recentTasks) {
foreach ($t in $recentTasks) {
$report += [pscustomobject]@{ Check = "New Scheduled Task (7d)"; Finding = "$($t.TaskPath)$($t.TaskName) created $($t.Date)"; Severity = "Investigate" }
}
} else { $report += [pscustomobject]@{ Check = "New Scheduled Task (7d)"; Finding = "None"; Severity = "OK" } }
} catch { $report += [pscustomobject]@{ Check = "New Scheduled Task (7d)"; Finding = "Enumeration failed: $($_.Exception.Message)"; Severity = "Review" } }
# 3) Volume Shadow Copy status — ransomware operators delete these before encryption
$shadows = Get-WmiObject Win32_ShadowCopy -ErrorAction SilentlyContinue
$shadowCount = ($shadows | Measure-Object).Count
$report += [pscustomobject]@{ Check = "Volume Shadow Copies"; Finding = "$shadowCount shadow copies present"; Severity = $(if ($shadowCount -eq 0) {"CRITICAL - verify this was not adversary deletion (Event 7036/7045 + vssadmin logs)"} else {"OK"}) }
# 4) PsExec-style / random-name services (lateral movement residue)
$susServices = Get-CimInstance Win32_Service | Where-Object {
$_.Name -match '^[A-Za-z0-9]{8}$' -or
$_.PathName -match 'PSEXESVC|paexec|csexec|ADMIN\$|\\Users\\Public\\|\\Windows\\Temp\\'
} | Select-Object Name, DisplayName, PathName, State
if ($susServices) {
foreach ($s in $susServices) {
$report += [pscustomobject]@{ Check = "Suspicious Service"; Finding = "$($s.Name) [$($s.State)] -> $($s.PathName)"; Severity = "Investigate" }
}
} else { $report += [pscustomobject]@{ Check = "Suspicious Service"; Finding = "None detected"; Severity = "OK" } }
# 5) Archive tooling in user-writable paths (data staging indicator)
$archiveHits = Get-ChildItem -Path "$env:PUBLIC","$env:TEMP","$env:USERPROFILE\Downloads" -Recurse -Include "7z.exe","rar.exe","7za.exe","winrar.exe" -ErrorAction SilentlyContinue | Select-Object FullName, LastWriteTime
if ($archiveHits) {
foreach ($a in $archiveHits) {
$report += [pscustomobject]@{ Check = "Archive Tool in User Path"; Finding = "$($a.FullName) (modified $($a.LastWriteTime))"; Severity = "Investigate" }
}
} else { $report += [pscustomobject]@{ Check = "Archive Tool in User Path"; Finding = "None"; Severity = "OK" } }
# 6) Recent failed logon burst (RDP/VPN brute force residue)
$failed = Get-WinEvent -FilterHashtable @{ LogName='Security'; Id=4625; StartTime=$cutoff } -MaxEvents 500 -ErrorAction SilentlyContinue
$failCount = ($failed | Measure-Object).Count
$report += [pscustomobject]@{ Check = "Failed Logons (7d)"; Finding = "$failCount failed logons"; Severity = $(if ($failCount -gt 100) {"Investigate - possible brute force"} else {"OK"}) }
$report | Sort-Object Severity | Format-Table -AutoSize -Wrap
$report | Export-Csv -Path ".\n0n_triage_$(hostname)_$(Get-Date -Format 'yyyyMMdd_HHmm').csv" -NoTypeInformation
Write-Host "`nTriage CSV exported. Any 'Investigate' or 'CRITICAL' finding warrants escalation to IR." -ForegroundColor Yellow
Incident Response Priorities
T-minus detection checklist (before encryption fires)
Opportunistic gangs with N0N's profile rarely encrypt immediately. Watch for:
- Shadow copy deletion (vssadmin/wmic/bcdedit) — the single highest-fidelity pre-detonation signal. Alert, don't log.
- Archive tool execution on servers — 7z/rar on a file server or DC outside a backup window is staging until proven otherwise.
- New service installations with random 8-character names — PsExec-style lateral movement.
- Mass SMB reads concentrated on file shares followed by outbound spikes to consumer cloud storage (MEGA, pCloud, Backblaze) or rclone-style endpoints.
- EDR/AV tampering events — service stop attempts on Defender, CrowdStrike, SentinelOne; disabled tamper protection via registry.
- Unusual VPN logins at odd hours from ISP/hosting ASNs the org has never authenticated from — the classic IAB-purchased-credential pattern.
Critical assets this profile of gang prioritizes for exfiltration
- File shares and NAS with HR, finance, legal, and customer data (the leak-site leverage material)
- Email archives of executives and legal counsel
- Databases and backups (they exfiltrate the backup, then destroy the originals)
- CI/CD and build servers (source code, secrets, signing keys — note the TeamCity KEV overlap)
- IdP artifacts: AD database (ntds.dit), ADFS/Azure AD token-signing material
Containment actions, ordered by urgency
- Isolate, don't power off suspected staging hosts — preserve memory for forensics; kill network egress first.
- Block known exfil destinations at the egress proxy/firewall (consumer cloud storage domains, unapproved file-transfer services).
- Force-rotate credentials for any account seen authenticating to a staging host; assume domain-wide Kerberos exposure if a DC is touched (krbtgt double-reset procedure).
- Disable inbound VPN/RDP from non-allowlisted geographies/ASNs immediately; audit all VPN accounts created or re-enabled in the last 90 days.
- Snapshot and verify backups NOW — confirm at least one offline/immutable copy predates the earliest suspicious event.
- Engage IR retainers and legal/comms before any leak-site countdown expires; do not let the gang's timer set your disclosure timeline.
Hardening Recommendations
Immediate (24 hours)
- Patch the KEV edge stack: Verify remediation status for CVE-2026-59310 (vCenter), CVE-2026-50751 (Check Point IKEv1), CVE-2026-20316 (Cisco FMC), and CVE-2026-63077 (TeamCity) — or take the affected management interfaces off the internet entirely. These are confirmed ransomware-used vulnerabilities.
- Deploy the Sigma rules above and the Sentinel hunt query; set shadow-copy-deletion detections to page, not digest.
- Audit internet-exposed RDP and VPN — enumerate with the triage script; require MFA on every remote-access path; block VPN logins from hosting-provider ASNs where business-viable.
- Disable Office macros from the internet (Mark-of-the-Web enforcement) via Group Policy if not already done.
- Block consumer cloud storage upload domains at the egress layer for servers (workstations per policy).
Short-term (2 weeks)
- Immutable/offline backups: Move at least one backup tier to object-lock/immutable storage with separate credentials from production AD. Test a restore.
- Segmentation: Isolate backup infrastructure, build servers (TeamCity), and virtualization management (vCenter) into dedicated enclaves reachable only from hardened jump hosts.
- Identity hardening: Tier-0 isolation for domain admins; gMSA or LAPS for service/local admin accounts; alert on any interactive logon by service accounts.
- Third-party/service-provider review: Several N0N listings claim service providers (BPO, ISP, IT services, hosted ed-tech). Inventory which providers hold your data and require incident-notification SLAs — your breach exposure may arrive via a supplier's leak-site listing, not your own telemetry.
- EDR tamper protection audit: Confirm tamper protection is enforced fleet-wide and that EDR service-stop events generate high-severity alerts.
Security Arsenal monitors ransomware leak sites continuously and translates criminal claims into defensive action. All victim listings in this briefing are unverified threat-actor claims. If your organization is named and you wish to provide context or request a correction, contact security@securityarsenal.com.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.