Back to Intelligence

N0N Ransomware Gang: 4 Leak-Site Listings Across Tech, Finance & Healthcare — Sector Analysis & Detection Rules

SA
Security Arsenal Team
October 8, 2026
12 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-09 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

N0N Ransomware Gang: 4 Leak-Site Listings Across Tech, Finance & Healthcare — Sector Analysis & Detection Rules

Executive Summary

Monitoring of ransomware gang N0N's dark web leak site via ransomware.live shows 4 victim listings published between 2026-10-05 and 2026-10-07, spanning Technology, Financial Services, and Healthcare organizations in the United States and Canada. These are claims made by a criminal actor on its own infrastructure — none constitute a confirmed breach. Only one of the four listings (Chibitek) was independently observed by a second leak-site crawler; the remaining three appear on a single source only and cannot yet be verified as even existing on the gang's site.

Regardless of verification status, the targeting pattern is actionable: N0N's claimed victim set concentrates in data-rich, downtime-intolerant sectors that overlap with the attack surface exposed by five currently exploited CVEs in the CISA KEV catalog (VMware vCenter, JetBrains TeamCity, Cisco FMC, Check Point Security Gateway, and Nx Console). Security teams in these sectors should treat this activity cluster as a trigger to run the detection content below, not as confirmation that any named organization has been compromised.

Sourcing & Verification

  • Corroboration status: 1 of 4 listings was independently observed by a second leak-site crawler (Chibitek, published 2026-10-07). The other 3 listings (Company #1, Company #2, Company #3, all published 2026-10-05) appear on ransomware.live only, with no second-crawler confirmation that the postings even exist.
  • What inclusion means: Every listing in this briefing reflects the threat actor's claim published on its own leak site. Inclusion here is not confirmation of a breach. No corroboration tier in this dataset confirms a compromise — only the named organization or its regulator can do that.
  • Disputes and denials: A named organization may dispute its listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable, so neither silence nor denial settles the question.
  • Corrections: Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — N0N

Note: Public attribution on N0N is limited. The profile below combines observed leak-site behavior with TTPs consistent with the double-extortion ecosystem it operates in. Where intelligence is thin, we flag it.

  • Aliases: No confirmed aliases. The stylized "N0N" branding should not be conflated with similarly named actors; track by leak-site infrastructure and onion address rather than name alone.
  • Operating model: Consistent with a closed or small-affiliate RaaS operation. The low posting volume (4 listings in the observation window) suggests either a newer operation, a deliberate low-and-slow tempo, or selective disclosure — not necessarily low activity.
  • Ransom demands: No published demand figures for this cluster. Comparable actors targeting mid-market technology and healthcare firms typically demand mid-six to low-seven figures, scaling to claimed data volume.
  • Initial access methods: Sector-typical vectors are exposed VPN/firewall appliances, RDP, phishing with macro- or script-based payloads, and CI/CD or developer-tooling compromise. The five KEV entries below map directly onto these vectors and are hypothesized exposure paths, not confirmed initial access for any named listing.
  • Extortion model: Double extortion — the existence of a leak site implies data theft claims accompany encryption. Listings that name organizations without published data samples often indicate ongoing (or failed) negotiation.
  • Dwell time: Unknown for N0N specifically. Comparable crews average 5–11 days from initial access to detonation; the staging behaviors in the Detection Engineering section typically begin 48–72 hours before encryption.

Current Campaign Analysis

Claimed listings (unverified threat-actor claims):

OrganizationSectorCountryPublishedCorroboration
ChibitekTechnologyUS2026-10-07Multi-source (posting observed by two crawlers; breach unconfirmed)
Company #3TechnologyUS2026-10-05Single-source
Company #2Financial ServicesCA2026-10-05Single-source
Company #1HealthcareUS2026-10-05Single-source
  • Sector targeting: Technology (2 of 4), Financial Services (1), Healthcare (1) — all high-data-value, high-pressure sectors where downtime and regulatory exposure maximize leverage.
  • Geographic concentration: 3 of 4 listings are US organizations; 1 is Canadian. This is a North America-focused claimed campaign.
  • Victim profile: With only 4 listings and no published revenue data, firm conclusions aren't supportable. The sector mix is consistent with mid-market targeting — organizations large enough to pay, small enough to lack 24/7 SOC coverage.
  • Posting frequency: 3 listings on 2026-10-05 followed by 1 on 2026-10-07 suggests batch posting, a common pattern where a crew processes multiple intrusions through a single access wave and publishes in clusters to maximize pressure.
  • CVE linkage (hypothesis only): We have no evidence tying any specific CVE to any specific listing. However, N0N's sector focus overlaps heavily with the exposed attack surface in CISA KEV: CVE-2026-59310 (VMware vCenter path traversal — ubiquitous in all three sectors), CVE-2026-63077 (JetBrains TeamCity deserialization — a direct hit on technology-sector CI/CD pipelines), CVE-2026-20316 (Cisco FMC hard-coded password — perimeter management plane), CVE-2026-50751 (Check Point Security Gateway improper authentication — VPN edge), and CVE-2026-48027 (Nx Console embedded malicious code — developer toolchain supply chain). Teams operating any of these products should assume active exploitation interest.

Detection Engineering

The following content targets the TTP cluster typical of N0N's operating model: edge/VPN exploitation and phishing for access, PsExec/WMI and Cobalt Strike for lateral movement, and staging/exfiltration prior to encryption. Tune thresholds to your environment.

YAML
---
title: Suspicious Child Process from VPN/Firewall or CI Service Account
description: Detects shell or scripting interpreter spawned by edge-device, hypervisor management, or CI/CD service processes — consistent with post-exploitation of appliances such as vCenter, TeamCity, or VPN gateways. Hypothesis-level mapping to N0N sector exposure (CVE-2026-59310, CVE-2026-63077, CVE-2026-50751).
status: experimental
author: Security Arsenal Threat Intelligence
date: 2026/10/09
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|contains:
      - '\tomcat'
      - '\teamcity'
      - '\vpxd'
      - '\httpd'
      - '\nginx'
    ParentCommandLine|contains:
      - 'teamcity'
      - 'vCenter'
      - 'vpn'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\rundll32.exe'
      - '\mshta.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate CI/CD build agents invoking shells (tune per TeamCity/vCenter host)
  - Vendor update mechanisms
level: high
tags:
  - attack.initial_access
  - attack.t1190
  - attack.t1059
---
title: Office Macro Spawning Scripting or Download Cradle
description: Detects Office applications spawning script interpreters, mshta, or certutil — consistent with phishing-macro initial access used by double-extortion crews including those matching N0N's profile.
status: experimental
author: Security Arsenal Threat Intelligence
date: 2026/10/09
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\outlook.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
      - '\rundll32.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare; legitimate Office documents should not spawn these binaries in most environments
level: high
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.t1059
---
title: Pre-Ransomware Staging - Shadow Copy Deletion and Mass Archive Creation
description: Detects Volume Shadow Copy tampering, backup catalog deletion, or archive-tool execution against multiple directories — behaviors observed in the 48-72 hours before ransomware detonation and data exfiltration in double-extortion operations.
status: experimental
author: Security Arsenal Threat Intelligence
date: 2026/10/09
logsource:
  category: process_creation
  product: windows
detection:
  selection_vss:
    CommandLine|contains:
      - 'vssadmin delete shadows'
      - 'vssadmin Delete Shadows'
      - 'wmic shadowcopy delete'
      - 'bcdedit'
      - 'wbadmin delete catalog'
      - 'resize shadowstorage'
  selection_archive:
    Image|endswith:
      - '\7z.exe'
      - '\rar.exe'
      - '\winrar.exe'
    CommandLine|contains:
      - ' a '
      - ' -p'
  condition: 1 of selection_*
falsepositives:
  - Backup administrators running legitimate shadow copy maintenance
  - Software packaging workflows using archivers
level: critical
tags:
  - attack.impact
  - attack.t1490
  - attack.t1560.001
  - attack.defense_evasion

Hunt query for Microsoft Sentinel covering lateral movement and pre-encryption staging (PsExec/service creation, WMI remote execution, RDP brute-force clustering):

KQL — Microsoft Sentinel / Defender
// N0N-profile hunt: lateral movement + pre-ransomware staging (7-day window)
let Lookback = 7d;
let SuspiciousServices = dynamic(["PSEXESVC", "paexec", "csexec", "remcom"]);
let RdpBrute =
    SecurityEvent
    | where TimeGenerated > ago(Lookback)
    | where EventID == 4625 and LogonType in (3, 10)
    | summarize FailedAttempts = count(), DistinctAccounts = dcount(Account) by IpAddress, Computer, bin(TimeGenerated, 1h)
    | where FailedAttempts >= 20 or DistinctAccounts >= 10
    | project RdpWindow = TimeGenerated, Computer, IpAddress, FailedAttempts, DistinctAccounts;
let LateralSvc =
    SecurityEvent
    | where TimeGenerated > ago(Lookback)
    | where EventID == 7045
    | where ServiceName has_any (SuspiciousServices)
       or ServiceFileName has_any ("\\ADMIN$", "\\C$", "temp\\")
    | project SvcTime = TimeGenerated, Computer, Account, ServiceName, ServiceFileName;
let WmiRemote =
    SecurityEvent
    | where TimeGenerated > ago(Lookback)
    | where EventID == 4688
    | where Process has "wmic.exe" and CommandLine has_any ("/node:", "process call create")
    | project WmiTime = TimeGenerated, Computer, Account, CommandLine;
let Staging =
    union
        (DeviceProcessEvents
        | where TimeGenerated > ago(Lookback)
        | where ProcessCommandLine has_any ("vssadmin delete shadows", "shadowcopy delete", "wbadmin delete catalog", "resize shadowstorage")
        | project StageTime = TimeGenerated, DeviceName, InitiatingProcessAccountName, ProcessCommandLine),
        (DeviceProcessEvents
        | where TimeGenerated > ago(Lookback)
        | where FileName in~ ("rclone.exe", "megasync.exe", "winscp.exe")
           or ProcessCommandLine has "mega.nz"
        | project StageTime = TimeGenerated, DeviceName, InitiatingProcessAccountName, ProcessCommandLine);
LateralSvc
| join kind=leftouter (WmiRemote) on Computer
| join kind=leftouter (Staging) on $left.Computer == $right.DeviceName
| join kind=leftouter (RdpBrute) on Computer
| summarize arg_max(SvcTime, *) by Computer, ServiceName
| project Computer, SvcTime, ServiceName, ServiceFileName, WmiTime, StageTime, ProcessCommandLine, IpAddress, FailedAttempts
| order by SvcTime desc;

Rapid-response PowerShell: enumerate recently created scheduled tasks, check exposed RDP, and inventory Volume Shadow Copy state on a suspect host.

PowerShell
# Security Arsenal - N0N rapid triage script (run elevated, per host)
$out = "C:\IR_Triage_$(hostname)_$(Get-Date -Format yyyyMMdd_HHmmss).txt"
"=== Scheduled tasks created/modified in last 7 days ===" | Out-File $out
Get-ScheduledTask | ForEach-Object {
    $i = $_ | Get-ScheduledTaskInfo
    [PSCustomObject]@{ Name=$_.TaskName; Path=$_.TaskPath; LastRun=$i.LastRunTime; Author=$_.Author; Action=($_.Actions | ForEach-Object {$_.Execute + ' ' + $_.Arguments}) -join ';' }
} | Where-Object { $_.LastRun -gt (Get-Date).AddDays(-7) -or $_.Author -notmatch 'Microsoft' } |
  Format-Table -AutoSize | Out-File $out -Append

"=== RDP exposure ===" | Out-File $out -Append
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
"RDP Enabled (0=yes): $($rdp.fDenyTSConnections)" | Out-File $out -Append
"NLA Required: $((Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue).UserAuthentication)" | Out-File $out -Append
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue | Format-Table LocalAddress,LocalPort,State | Out-File $out -Append

"=== Failed logons (4625) last 72h - brute force check ===" | Out-File $out -Append
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddHours(-72)} -ErrorAction SilentlyContinue |
  Group-Object { $_.Properties[19].Value } | Sort-Object Count -Descending | Select-Object -First 15 Count,Name |
  Format-Table -AutoSize | Out-File $out -Append

"=== Volume Shadow Copies (should exist; absence post-incident is a red flag) ===" | Out-File $out -Append
vssadmin list shadows | Out-File $out -Append
Get-CimInstance Win32_ShadowCopy | Select-Object ID, InstallDate, VolumeName | Format-Table -AutoSize | Out-File $out -Append

"=== Suspicious executables in Temp/AppData modified last 7 days ===" | Out-File $out -Append
Get-ChildItem "$env:TEMP","$env:LOCALAPPDATA" -Recurse -Include *.exe,*.dll,*.ps1 -ErrorAction SilentlyContinue |
  Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) } | Select-Object FullName, LastWriteTime |
  Format-Table -AutoSize | Out-File $out -Append
Write-Host "Triage written to $out"

Incident Response Priorities

T-minus detection checklist (before encryption fires):

  • New services named PSEXESVC or with binaries in ADMIN$/Temp paths (Event ID 7045)
  • vssadmin delete shadows, wbadmin delete catalog, or bcdedit recovery-disable commands
  • Bulk archive creation (7z/rar with password flags) on file servers or database hosts
  • Exfil tooling: rclone, MEGASync, WinSCP, or unusual sustained outbound HTTPS to rare destinations
  • Impossible-travel or off-hours logons to VPN/VDI following an edge-device advisory window
  • TeamCity/CI build agents spawning shells or writing to non-standard output paths

Critical assets this profile historically prioritizes for exfiltration (sector-aligned):

  • Healthcare: patient records, EHR exports, imaging archives — highest regulatory leverage
  • Financial services: client PII, transaction records, regulatory filings
  • Technology: source code repositories, CI/CD secrets and signing keys, customer data — note that a TeamCity compromise can yield downstream supply-chain access

Containment, ordered by urgency:

  1. Isolate affected segments at the switch/VLAN level — do not power off hosts (preserve memory evidence)
  2. Disable the suspected initial-access vector: pull the edge appliance or CI server from the network
  3. Force-reset credentials for any account observed in lateral movement telemetry; prioritize service and admin accounts; revoke sessions/tokens
  4. Block identified exfil destinations at egress; snapshot firewall and proxy logs before retention rolls
  5. Verify backup integrity and confirm offline/immutable copies are genuinely unreachable from production
  6. Engage IR retainer and legal counsel on disclosure obligations before any external statement

Hardening Recommendations

Immediate (24 hours):

  • Patch or isolate the five KEV entries: CVE-2026-59310 (vCenter), CVE-2026-63077 (TeamCity), CVE-2026-20316 (Cisco FMC), CVE-2026-50751 (Check Point Gateway), CVE-2026-48027 (Nx Console — remove malicious versions and rotate any credentials on developer machines where it ran). These are confirmed actively exploited with ransomware use.
  • Enforce MFA on all VPN, RDP, and remote-management paths; disable RDP from the internet outright
  • Block Office macros from internet-sourced files; deploy the Sigma rules and KQL query above
  • Alert on shadow-copy deletion and lock vssadmin/wbadmin behind admin-tier workstations

Short-term (2 weeks):

  • Segment CI/CD infrastructure (TeamCity and build agents) away from production and domain controllers; treat developer workstations as a distinct, monitored tier
  • Egress filtering with destination reputation blocking for known exfil endpoints (rclone remotes, MEGA, anonymous file shares)
  • Move backups to immutable/offline storage with credentials separated from the production domain
  • Deploy canary files/credentials on file servers to get early, high-fidelity pre-encryption signals
  • Stand up leak-site monitoring for your organization name so a criminal's claim reaches you in hours, not weeks

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.