Back to Intelligence

N0N Ransomware Gang: 4 New Leak-Site Claims — Sector Targeting Analysis & Detection Rules

SA
Security Arsenal Team
October 9, 2026
10 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-09 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

Executive Summary

N0N has listed four organizations on its dark web leak site across a tight posting window: three claims published 2026-10-05 and one published 2026-10-07. The actor names Chibitek, Company #3, Company #2, and Company #1. Only the Chibitek posting was independently observed by a second leak-site crawler; the other three appear on ransomware.live only. These are criminal accusations, not confirmed breaches. Technology, financial services, and healthcare organizations in the US and Canada should treat this as a sector-exposure signal: validate edge VPN/firewall patching, hunt for pre-encryption staging, and prepare extortion-response decision paths before any encryption event.

Sourcing & Verification

  • Corroboration status: 1 of 4 listings was independently observed by a second leak-site crawler; 3 of 4 are single-source and appear on ransomware.live only.
  • Inclusion reflects the threat actor's claim and is NOT confirmation of a breach, intrusion, data theft, or operational impact.
  • A named organization may dispute the listing. A denial is likewise not proof the claim is false; disclosure obligations vary by jurisdiction, contract, regulator, and materiality, and not every incident is reportable. Neither silence nor denial settles the question.
  • Security Arsenal will publish corrections and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — N0N

  • Known aliases: none are reliably corroborated in the provided dataset. Treat any alias mapping outside primary leak-site evidence as low confidence until independently validated.
  • Operating model: not confirmed from this dataset. The leak-site pattern is consistent with contemporary double-extortion operations; whether N0N is RaaS, closed group, or affiliate-driven should be treated as unassessed.
  • Typical ransom demands: not provided for this campaign. For sector planning, assume demands scale to perceived ability to pay, regulatory exposure, and stolen-data sensitivity rather than a fixed tariff.
  • Known initial access methods: no victim-specific vector is established here. Sector-relevant hypotheses include exploited edge services, VPN/firewall flaws, exposed RDP, phishing-driven execution, and abuse of build/CI or virtualization management planes.
  • Extortion approach: the presence of named listings indicates name-and-shame pressure consistent with double extortion; whether data was actually exfiltrated remains unverified for every named organization.
  • Average dwell time before detonation: not established in this dataset. Defensive planning should assume days-to-weeks for hands-on intrusion and hours for mass encryption once staging completes.

Current Campaign Analysis

Sectors being targeted

From the supplied listings only: Technology, Financial Services, and Healthcare. N0N has listed Chibitek and Company #3 under Technology; Company #2 under Financial Services; Company #1 under Healthcare. Do not treat any listing as proof of compromise.

Geographic concentration

US and CA only in this slice: Chibitek, Company #3, and Company #1 are tagged US; Company #2 is tagged CA. This is a small sample and should not be extrapolated into a durable regional doctrine.

Victim profile

Company size and revenue are not provided and should not be invented. The sector mix implies interest in organizations holding regulated data, intellectual property, payment-adjacent workflows, patient data, or operationally sensitive availability requirements. Assume mid-market through enterprise exposure until victim telemetry proves otherwise.

Observed posting frequency / escalation patterns

The cluster is compressed: Company #1, Company #2, and Company #3 were published 2026-10-05; Chibitek was published 2026-10-07. That cadence can indicate batch posting after separate intrusions, affiliate uploads, recycled access, or strategic leak-site timing. With only four listings and one multi-source observation, escalation cannot be confirmed.

CVE exposure hypothesis — not victim attribution

No evidence links any named organization to a specific CVE. At sector level, prioritize confirmed ransomware-used KEV items as exposure hypotheses: CVE-2026-59310 affecting Broadcom VMware vCenter; CVE-2026-63077 affecting JetBrains TeamCity; CVE-2026-20316 affecting Cisco Secure Firewall Management Center; CVE-2026-50751 affecting Check Point Security Gateway IKEv1 improper authentication; and CVE-2026-50751-adjacent supply-chain risk represented by CVE-2026-48027 affecting Nx Console. These matter because virtualization control planes, CI/CD, edge firewalls, VPNs, and developer tooling are common pre-ransomware access and staging points.

Detection Engineering

SIGMA

YAML
---
title: N0N Campaign - Edge or RDP Password Spray Followed by Successful Logon
id: 7f2a9b10-6b0a-4f0d-9d6d-n0nrdp001
status: experimental
description: Detects bursts of failed remote authentication followed by success from the same source, consistent with VPN or RDP password attacks preceding ransomware intrusion.
author: Security Arsenal Detection Engineering
date: 2026/10/09
references:
  - https://securityarsenal.com/darkside
logsource:
  category: authentication
  product: windows
detection:
  selection_failed:
    EventID: 4625
  selection_success:
    EventID: 4624
    LogonType:
      - 3
      - 10
  condition: selection_failed and selection_success
timeframe: 10m
falsepositives:
  - Vulnerability scanners and misconfigured service accounts
level: high
tags:
  - attack.t1110
  - attack.t1078
  - attack.t1133
---
title: N0N Campaign - PsExec or WMI Style Remote Service Creation
id: 8d21a4c2-71ab-4f52-a771-n0nlat002
status: experimental
description: Detects remote service creation and ADMIN$ style execution consistent with PsExec, WMI, or similar lateral movement before ransomware deployment.
author: Security Arsenal Detection Engineering
date: 2026/10/09
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\psexec.exe'
      - '\wmic.exe'
      - '\sc.exe'
      - '\rundll32.exe'
  selection_cmd:
    CommandLine|contains:
      - 'ADMIN$'
      - 'psexec'
      - 'wmic'
      - 'call create'
      - 'service create'
      - 'start service'
  condition: selection_img and selection_cmd
falsepositives:
  - Legitimate administration by EDR, SCCM, or remote support tooling
level: high
tags:
  - attack.t1021.002
  - attack.t1047
  - attack.t1569.002
---
title: N0N Campaign - Pre Encryption Staging and Shadow Copy Tampering
id: 4ab6c901-2c1f-4c77-9a10-n0nstg003
status: experimental
description: Detects data staging archives, shadow copy deletion, backup inhibition, and mass rename behavior often observed immediately before detonation.
author: Security Arsenal Detection Engineering
date: 2026/10/09
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_tools:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wbadmin.exe'
      - '\bcdedit.exe'
      - '\7z.exe'
      - '\rar.exe'
      - '\robocopy.exe'
      - '\rclone.exe'
  selection_args:
    CommandLine|contains:
      - 'delete shadows'
      - 'resize shadowstorage'
      - 'delete catalog'
      - 'recoveryenabled no'
      - 'bootstatuspolicy ignoreallfailures'
      - 'a -v'
      - 'mcloud'
      - 'copy --transfers'
  condition: selection_tools and selection_args
falsepositives:
  - Backup administrators, archiving jobs, and legitimate cloud sync tooling
level: critical
tags:
  - attack.t1490
  - attack.t1560
  - attack.t1567
  - attack.t1486

KQL - Microsoft Sentinel hunt

KQL — Microsoft Sentinel / Defender
let Lookback = 7d;
let SuspectTools = dynamic(["psexec.exe","wmic.exe","rclone.exe","7z.exe","rar.exe","vssadmin.exe","wbadmin.exe","bcdedit.exe"]);
let Failed = SecurityEvent
| where TimeGenerated >= ago(Lookback)
| where EventID == 4625
| summarize FailedCount=count(), FailedHosts=dcount(Computer), FailedUsers=dcount(TargetAccount) by IpAddress, bin(TimeGenerated, 10m);
let Success = SecurityEvent
| where TimeGenerated >= ago(Lookback)
| where EventID == 4624 and LogonType in (3,10)
| summarize SuccessHosts=dcount(Computer), SuccessUsers=dcount(TargetAccount), FirstSuccess=min(TimeGenerated) by IpAddress;
let EdgeBurst = Failed
| join kind=inner Success on IpAddress
| where FailedCount >= 20 and FirstSuccess between (TimeGenerated .. TimeGenerated + 10m)
| project IpAddress, FailedCount, FailedHosts, FailedUsers, SuccessHosts, SuccessUsers, FirstSuccess;
let Lateral = DeviceProcessEvents
| where TimeGenerated >= ago(Lookback)
| where FileName in~ (SuspectTools)
| summarize ToolHits=count(), Tools=make_set(FileName), Hosts=make_set(DeviceName), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated) by InitiatingProcessAccountName;
EdgeBurst
| join kind=leftouter Lateral on $left.IpAddress == $right.InitiatingProcessAccountName
| project IpAddress, FailedCount, SuccessHosts, FirstSuccess, ToolHits, Tools, Hosts, FirstSeen, LastSeen
| order by FirstSuccess desc;

Rapid response script

PowerShell
$ErrorActionPreference='SilentlyContinue'
$since=(Get-Date).AddDays(-7)
'=== RDP exposure ==='
Get-NetTCPConnection -State Listen -LocalPort 3389 | Select-Object LocalAddress,LocalPort,OwningProcess
'=== New scheduled tasks last 7 days ==='
Get-ScheduledTask | ForEach-Object { $i=$_ | Get-ScheduledTaskInfo; [pscustomobject]@{Task=$_.TaskName;Path=$_.TaskPath;Created=$i.CreationTime;LastRun=$i.LastRunTime;NextRun=$i.NextRunTime} } | Where-Object {$_.Created -ge $since} | Sort-Object Created -Descending
'=== Suspicious processes ==='
Get-Process | Where-Object {$_.Name -match 'psexec|rclone|7z|rar|vssadmin|wbadmin|bcdedit|wmic'} | Select-Object Name,Id,Path,StartTime
'=== Shadow copies ==='
Get-CimInstance Win32_ShadowCopy | Select-Object ID,InstallDate,VolumeName,DeviceObject
'=== Recent security failures by source ==='
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4625;StartTime=$since} -MaxEvents 5000 | Group-Object {$_.Properties[19].Value} | Sort-Object Count -Descending | Select-Object -First 25 Name,Count

Incident Response Priorities

T-minus detection checklist — before encryption fires

  • Confirm whether edge authentication shows password spray, impossible travel, new MFA bypass prompts, or logons from hosting providers and TOR-adjacent infrastructure.
  • Hunt for new local admin creation, Group Policy changes, service installation, remote scheduled tasks, WMI subscriptions, and unexpected use of PsExec-like tooling.
  • Look for staging directories on file shares, sudden archive creation, cloud sync binaries, NAS backup access, and large reads from finance, EHR, source code, or executive repositories.
  • Validate shadow copies, backup catalogs, immutable snapshots, and backup admin sessions before assuming recovery is intact.
  • Treat vCenter, TeamCity, Cisco FMC, Check Point gateways, developer workstations, and build agents as priority blast-radius controls due to the KEV exposure list above.

Critical assets this gang historically prioritizes for extortion leverage

Specific N0N exfiltration preferences are not established by the supplied data. For the listed sectors, prioritize protection and monitoring around source code and CI secrets for technology firms; customer PII, payment workflows, trading or finance records for financial services; and EHR exports, imaging archives, claims data, and clinical downtime procedures for healthcare. Frame these as likely leverage classes, not proof that any named organization lost data.

Containment actions ordered by urgency

  1. Isolate suspected hosts from the network without powering off if memory capture is feasible.
  2. Disable or reset implicated accounts, revoke tokens and sessions, and rotate exposed service, VPN, CI, and hypervisor credentials.
  3. Block egress to newly observed file-transfer destinations and suspend nonessential sync tools while preserving evidence.
  4. Protect backups: verify immutability, remove backup-plane access from standard admin tiers, and snapshot clean recovery points.
  5. Segment vCenter, firewall management, CI/CD, and backup consoles from general user VLANs.
  6. Engage legal, privacy, communications, insurance, and regulator workflows early; do not validate or refute a criminal claim publicly without evidence review.

Hardening Recommendations

Immediate — 24 hours

  • Patch or mitigate CISA KEV items on internet-facing and management-plane assets: Broadcom VMware vCenter CVE-2026-59310, JetBrains TeamCity CVE-2026-63077, Cisco Secure FMC CVE-2026-20316, Check Point Security Gateway CVE-2026-50751, and developer-tool exposure represented by Nx Console CVE-2026-48027.
  • Enforce phishing-resistant MFA on VPN, firewall, hypervisor, CI/CD, backup, and remote-support portals; disable legacy IKEv1 where not required after Check Point review.
  • Disable exposed RDP or place it behind VPN/ZTNA with account lockout, NLA, and source-IP restrictions; alert on 4625 bursts followed by 4624 type 3 or 10.
  • Block or tightly control PsExec-style remote service creation, rclone/7z/rar on servers, and vssadmin/wbadmin/bcdedit execution outside change windows.
  • Verify backup immutability, offline copies, restore tests, and separation of backup admin credentials from domain admin.

Short-term — two weeks

  • Move management planes for vCenter, FMC, Check Point, TeamCity, backup, and EDR into isolated admin networks with brokered access and session recording.
  • Deploy egress allowlisting for servers and build agents; require DNS, proxy, and cloud-storage logging with alerting on rare destinations.
  • Implement tiered administration, just-in-time privilege, gMSA or vaulted service accounts, and automatic rotation after any admin session on critical assets.
  • Add detection coverage for archive staging, shadow-copy tampering, mass file rename, remote thread creation, and anomalous SMB reads against crown-jewel shares.
  • Run an extortion tabletop that assumes data theft is claimed but unproven: decision tree for contact, negotiation counsel, regulator triggers, customer notice, and correction handling.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.