Classification: TLP:CLEAR | Publication Date: 2026-09-29 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
N0N Ransomware Gang: 3 New Leak-Site Listings Targeting Manufacturing & Technology — Sector Analysis and Detection Engineering
Executive Summary
Monitoring of criminal leak-site infrastructure via ransomware.live shows that the ransomware group N0N has published three new victim listings in the past week, concentrated in the Manufacturing and Technology sectors across Great Britain and the United States. Between 2026-09-25 and 2026-09-29, N0N listed Precision Facades Ltd (Manufacturing, GB), Dediserve Ltd (Technology, GB), and TapClicks (Technology, US) on its dark web leak site.
It is critical to understand what this data is and is not: a leak-site listing is a claim made by a criminal actor. This briefing does not state or imply that any named organization was breached, attacked, or is managing an active incident. N0N claims to have compromised these organizations; only the organizations themselves or their regulators can confirm or refute an intrusion.
For defenders, the actionable signal is the pattern: a two-sector, two-country concentration consistent with opportunistic exploitation of internet-facing infrastructure (VPN gateways, virtualization management planes, CI/CD tooling). This briefing provides detection engineering content — Sigma rules, KQL hunting queries, and a rapid-response script — mapped to N0N's observed tradecraft so security teams can hunt for pre-detonation activity in their own environments regardless of whether any individual claim proves accurate.
Sourcing & Verification
- Corroboration status: Of the 3 listings covered in this briefing, 2 were independently observed by a second leak-site crawler (Precision Facades Ltd, Dediserve Ltd). 1 listing (TapClicks) appears on a single source only — ransomware.live — with no second-crawler confirmation that the posting even exists. We flag single-source listings because crawler outages, site mirrors, and parsing errors can produce phantom entries.
- What corroboration means: Multi-source corroboration confirms only that the gang published the claim. No tier in this data confirms a breach. Inclusion in this briefing reflects the threat actor's accusation and nothing more.
- Disputes and denials: A named organization may dispute its listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question, and we make no inference from either.
- Corrections: Security Arsenal will publish corrections to this briefing if warranted, and we welcome contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — N0N
Note: N0N is a low-volume actor with limited public reporting. The profile below combines observations from its leak-site behavior with tradecraft consistent across similar mid-tier operations. Where attribution-specific data is thin, we say so.
- Aliases: No widely documented aliases. The group brands itself simply as "N0N" on its leak site. Low posting volume (3 listings in the last 100 tracked postings across the ecosystem window) suggests either a newer operation, a rebrand of a prior crew, or a selective targeting model.
- Operating model: Assessed as a closed or semi-closed group rather than a high-volume open RaaS. The low victim cadence and narrow sector focus are inconsistent with the affiliate-driven spray-and-pray model seen from major RaaS programs; it is more consistent with a small core team conducting hands-on intrusions.
- Ransom demands: No verified public figures for N0N specifically. Mid-tier groups with this victim profile typically demand in the low-to-mid six figures (USD), scaling to perceived victim revenue, with threats to publish exfiltrated data on a countdown timer.
- Initial access methods (typical for this actor class): Exploitation of exposed remote access services (VPN appliances, RDP), phishing with macro-laden or script-based payloads, and — increasingly across 2026 campaigns — abuse of edge/management infrastructure such as firewall management consoles and virtualization platforms. Supply-chain and tooling compromise (e.g., poisoned developer extensions) is an emerging vector in this ecosystem.
- Extortion approach: Double extortion is the standard model: data exfiltration precedes encryption, with leak-site publication used as leverage. N0N's own leak site is the pressure mechanism observed here.
- Dwell time: For comparable mid-tier actors, observed dwell time from initial access to detonation typically runs days to two weeks, with the most destructive activity (staging, exfiltration, encryption) compressed into the final 24–72 hours. That window is where detection matters most.
Current Campaign Analysis
Targeted sectors
The current cluster is split between Manufacturing and Technology:
- Manufacturing: Precision Facades Ltd (GB) — a building-envelope/facades firm. Manufacturing remains the most-ransomed sector globally because operational downtime is existentially expensive, creating maximum payment pressure.
- Technology: Dediserve Ltd (GB, hosting/cloud services) and TapClicks (US, marketing analytics platform). Technology and hosting providers are attractive because a single compromise can cascade to downstream customers, and analytics platforms aggregate large volumes of client data — prime double-extortion material.
Geographic concentration
2 of 3 listings are UK-based; 1 is US-based. The sample is too small to declare a UK-focused campaign, but the GB skew is worth noting for UK-domiciled manufacturers and managed/hosting providers.
Victim profile
Based on the listed organizations' sectors, the profile skews toward small-to-midsize enterprises (roughly 50–500 employees, estimated revenue in the ~$10M–$250M range) — organizations large enough to pay a meaningful ransom but frequently lacking 24/7 SOC coverage. This is the classic mid-tier-actor sweet spot.
Posting frequency / escalation pattern
Three listings in five days (2026-09-25, 2026-09-28, 2026-09-29) with an accelerating cadence — two postings in the final 48 hours. This pattern is consistent with either (a) a batch of intrusions from a single access wave being published as negotiations stall, or (b) a deliberate escalation to build leak-site credibility. Either way, expect additional listings in the near term.
CVE linkage — hypothesis only
We have no evidence tying any specific CVE to any named listing above. However, the following CISA KEV entries with confirmed ransomware use represent exactly the class of exposure mid-tier actors like N0N are known to exploit, and we flag them as sector-level hypotheses for defenders to prioritize:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Edge-VPN auth bypass is a top initial-access vector for ransomware crews.
- CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane compromise yields broad network control.
- CVE-2026-59310 — Broadcom VMware vCenter path traversal. vCenter access enables mass encryption of virtualized estates — the classic ransomware endgame.
- CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise enables supply-chain-style downstream spread — relevant given the Technology-sector targeting here.
- CVE-2026-50751's counterpart in developer tooling: CVE-2026-48027 — Nx Console embedded malicious code, illustrating the developer-tooling supply-chain vector relevant to technology firms.
If any of these products are internet-facing in your environment, treat patching as an emergency change, not a routine one.
Detection Engineering
The following detections target tradecraft common to N0N-class operations: VPN/edge exploitation followed by RDP lateral movement, PsExec/WMI-based tooling deployment, pre-encryption data staging with common archivers, and shadow-copy destruction immediately before detonation.
---
title: RDP Logon Following VPN Authentication - Potential Edge-to-Internal Pivot
id: 9f3a2c10-7b1e-4d5a-9c21-n0n000000001
status: experimental
description: Detects an interactive RDP logon (Type 10/3) from a source that authenticated via VPN within a short window, consistent with post-exploitation pivoting after edge-device compromise (e.g., CVE-2026-50751, CVE-2026-20316).
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/29
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
LogonType:
- 3
- 10
filter_vpn_ranges:
IpAddress|startswith:
- '10.'
- '172.16.'
- '192.168.'
condition: selection and filter_vpn_ranges
falsepositives:
- Legitimate administrative RDP from VPN address space
level: medium
tags:
- attack.lateral_movement
- attack.t1021.001
---
title: PsExec or WMI Remote Service Creation - Ransomware Tooling Deployment
id: 9f3a2c10-7b1e-4d5a-9c21-n0n000000002
status: experimental
description: Detects remote service creation events consistent with PsExec-style execution or WMI-deployed payloads, a hallmark of hands-on ransomware operators pushing encryptors and staging tools across the estate.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/29
logsource:
product: windows
service: system
detection:
selection:
EventID: 7045
ServiceName|contains:
- 'PSEXESVC'
- 'PAExec'
- 'csexec'
- 'RemCom'
selection_image:
EventID: 7045
ImagePath|contains:
- '\ADMIN$'
- '\IPC$'
- '\\127.0.0.1'
condition: 1 of selection*
falsepositives:
- Legitimate software deployment tooling (SCCM, PDQ) - baseline service names
level: high
tags:
- attack.lateral_movement
- attack.t1569.002
- attack.t1021.002
---
title: Pre-Ransomware Staging - Mass Archive Creation and Shadow Copy Deletion
id: 9f3a2c10-7b1e-4d5a-9c21-n0n000000003
status: experimental
description: Detects the classic pre-detonation combination - data staged with common archivers (rar/7z/winzip) and Volume Shadow Copy deletion via vssadmin, wmic, or diskshadow. High-confidence ransomware precursor.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/29
logsource:
category: process_creation
product: windows
detection:
selection_archive:
Image|endswith:
- '\rar.exe'
- '\7z.exe'
- '\7za.exe'
- '\winzip64.exe'
CommandLine|contains:
- ' a '
- ' -p'
- ' -hp'
selection_vss:
CommandLine|contains:
- 'vssadmin delete shadows'
- 'vssadmin Delete Shadows'
- 'wmic shadowcopy delete'
- 'resize shadowstorage'
- 'diskshadow'
- '/delete shadows'
condition: selection_archive or selection_vss
falsepositives:
- Backup software and IT archiving workflows - tune by parent process and account
level: high
tags:
- attack.impact
- attack.t1490
- attack.exfiltration
- attack.t1560.001
The KQL query below hunts the pre-ransomware staging chain in Microsoft Sentinel: unusual volume of file access followed by archive-tool execution and outbound transfer to rare external destinations — the exfiltration pattern that precedes double-extortion publication on a leak site.
// Hunt: Pre-ransomware data staging & exfiltration pattern (N0N-class tradecraft)
// Looks for: archiver execution -> large outbound transfer to rare destinations, within 24h
let lookback = 7d;
let staging_window = 24h;
let archive_procs = dynamic(["rar.exe","7z.exe","7za.exe","winrar.exe","winzip64.exe"]);
let StagingHosts =
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ (archive_procs)
| summarize FirstArchive=min(Timestamp), ArchiveCmdLines=make_set(ProcessCommandLine, 5) by DeviceId, DeviceName, InitiatingProcessAccountName;
let RareOutbound =
DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where ActionType == "ConnectionSuccess"
| where RemoteIPType == "Public"
| summarize Connections=count(), FirstSeen=min(Timestamp), Destinations=make_set(RemoteUrl, 10) by DeviceId, RemoteIP;
StagingHosts
| join kind=inner (RareOutbound) on DeviceId
| where FirstSeen >= FirstArchive and FirstSeen <= FirstArchive + staging_window
| where Connections > 50
| extend SuspicionScore = Connections
| project DeviceName, InitiatingProcessAccountName, FirstArchive, ArchiveCmdLines, RemoteIP, Connections, Destinations, SuspicionScore
| order by SuspicionScore desc
The PowerShell script below is a rapid-response triage tool: it checks for exposed RDP listeners, enumerates scheduled tasks created in the last 7 days (persistence), and inspects Volume Shadow Copy health — three checks that surface the N0N-class pre-detonation footprint in under a minute per host.
# Rapid-Response Triage: Pre-Ransomware Indicators (run elevated per host or via your RMM/EDR)
# Checks: exposed RDP, recent scheduled tasks (7d), shadow copy health
$ErrorActionPreference = 'SilentlyContinue'
$report = [ordered]@{}
# 1) RDP exposure check
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections).fDenyTSConnections -eq 0
$rdpPort = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber).PortNumber
$rdpListening = (Get-NetTCPConnection -LocalPort $rdpPort -State Listen) -ne $null
$nlaEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication).UserAuthentication -eq 1
$report['RDP_Enabled'] = $rdpEnabled
$report['RDP_Port'] = $rdpPort
$report['RDP_Listening'] = $rdpListening
$report['RDP_NLA_Enforced'] = $nlaEnabled
if ($rdpEnabled -and $rdpListening -and -not $nlaEnabled) { Write-Warning "RDP exposed WITHOUT NLA - brute-force/BlueKeep-class risk. Disable or restrict immediately." }
# 2) Scheduled tasks created in the last 7 days (persistence / staging)
$cutoff = (Get-Date).AddDays(-7)
$recentTasks = Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt $cutoff } | Select-Object TaskName, TaskPath, Date, @{n='Actions';e={($_.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }) -join ' | '}}
$report['RecentScheduledTasks'] = $recentTasks
if ($recentTasks) { Write-Warning "$($recentTasks.Count) scheduled task(s) created in last 7 days - review below."; $recentTasks | Format-List }
# 3) Volume Shadow Copy status
$shadows = Get-CimInstance Win32_ShadowCopy
$report['ShadowCopyCount'] = @($shadows).Count
if (@($shadows).Count -eq 0) { Write-Warning "NO Volume Shadow Copies present - consistent with vssadmin deletion (T1490) or simply no restore points configured. Correlate with process logs." }
# 4) Suspicious archiver artifacts in common staging dirs
$stagingHits = Get-ChildItem 'C:\Users','C:\ProgramData','C:\Windows\Temp' -Recurse -Include *.rar,*.7z -ErrorAction SilentlyContinue | Where-Object { $_.LastWriteTime -gt $cutoff -and $_.Length -gt 100MB } | Select-Object FullName, Length, LastWriteTime
$report['LargeRecentArchives'] = $stagingHits
if ($stagingHits) { Write-Warning "Large archives created in last 7 days - possible exfil staging."; $stagingHits | Format-List }
Write-Host "`n=== TRIAGE SUMMARY ===" -ForegroundColor Cyan
$report.GetEnumerator() | Where-Object { $_.Value -isnot [array] -and $_.Value -isnot [psobject] } | Format-Table -AutoSize
Incident Response Priorities
T-minus detection checklist — before encryption fires
For N0N-class actors, the final 24–72 hours are the highest-signal window. Hunt for:
- Archive-tool execution (rar.exe, 7z.exe) by non-IT accounts or on servers that never run them.
- New scheduled tasks or services created estate-wide in a short burst (mass staging/persistence).
- PsExec-style service creation (Event 7045) and ADMIN$/IPC$ writes across multiple hosts in sequence.
- vssadmin / wmic shadowcopy deletion or
bcdeditrecovery-disable commands — the strongest pre-detonation indicator. - Unusual outbound volume to rare IPs, cloud storage, or MEGA/file-sharing destinations in the 24h after archiving activity.
- EDR tampering: sensor service stops, exclusions added, or uninstall attempts.
Assets this actor class prioritizes for exfiltration
Given the Manufacturing/Technology targeting:
- For manufacturers: CAD/CAM designs, bill-of-materials and pricing data, customer contracts, ERP exports.
- For technology/hosting firms: customer databases, tenant credentials and API keys, source code repositories, support ticket archives (which often contain client secrets).
- Universally: HR/payroll records and executive mailboxes — the highest-leverage material for double extortion.
Containment actions, ordered by urgency
- Isolate, don't power off — network-isolate suspected hosts via EDR; preserve volatile memory for forensics.
- Disable compromised accounts and revoke sessions/tokens — including service accounts seen in lateral movement.
- Block edge access — if VPN/firewall management interfaces (Check Point, Cisco FMC) are implicated, restrict to allow-listed admin IPs or take offline pending patching.
- Protect backups — verify offline/immutable copies are intact and unreachable from production credentials before announcing containment.
- Preserve leak-site evidence — capture the listing (screenshots, timestamps, any posted samples) for legal, insurance, and regulatory purposes. Do not contact the actor without counsel involvement.
Hardening Recommendations
Immediate (24 hours)
- Patch or mitigate the KEV set if present in your environment: CVE-2026-50751 (Check Point), CVE-2026-20316 (Cisco FMC), CVE-2026-59310 (vCenter), CVE-2026-63077 (TeamCity), CVE-2026-48027 (Nx Console — audit for the malicious package version). These carry confirmed ransomware use.
- Enforce NLA and MFA on all RDP/VPN paths; disable RDP exposure to the internet entirely — place it behind VPN + MFA or remove it.
- Alert on vssadmin/wmic shadow deletion and archiver execution using the Sigma rules above — these fire before encryption.
- Verify backup immutability and confirm restore credentials are segregated from domain admin.
- Block macro execution from internet-sourced Office files (Mark-of-the-Web policy) and script interpreters for standard users.
Short-term (2 weeks)
- Segment the estate: separate management planes (vCenter, FMC, backup infrastructure) onto restricted networks with dedicated admin workstations (PAWs); ransomware crews win by reaching the management plane.
- Deploy egress filtering with rare-destination alerting — double extortion requires exfiltration; make large outbound transfers to unsanctioned destinations a page-worthy event.
- Implement tiered administration and eliminate standing Domain Admin use on servers and workstations.
- Stand up leak-site monitoring (directly or via a provider) so your organization learns of a claim from your SOC, not from a journalist.
- Tabletop the double-extortion scenario with legal, comms, and executives pre-aligned on decision authority — the extortion clock doesn't pause for internal deliberation.
This briefing reflects unverified threat-actor claims observed on criminal infrastructure. Security Arsenal will update or correct this assessment as verified information becomes available. Named organizations may contact us at security@securityarsenal.com.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.