Classification: TLP:CLEAR | Publication Date: 2026-09-23 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
N0N Ransomware Gang: 7 New Leak-Site Listings Across Tech, Retail, Finance & Government
Executive Summary
Security Arsenal's dark web monitoring observed 7 new victim listings on the N0N ransomware group's Tor-based leak site between 2026-09-18 and 2026-09-22, based on data aggregated by ransomware.live. The claimed victims span Technology, Retail & E-Commerce, Financial Services, and Government & Defense across six countries: Mali, Uzbekistan, the United States, Venezuela, Sweden, and Argentina.
Every one of the 7 listings is single-source: only one leak-site crawler observed each posting, with no independent second-crawler confirmation that the posting even exists on the gang's site. These are unverified claims by a criminal organization — not confirmed breaches. Organizations named include AFRICA-TECH, FinSoft, Fanatics, Inter, PayPal support operations (Transcom WorldWide), the Ministry of Education — Argentina, and Argentem Creek Partners.
Regardless of verification status, the campaign pattern is actionable: N0N continues to mix high-value Western financial/retail names with emerging-market telecom and government targets, consistent with an access-broker-fed double-extortion operation. Defenders in the named sectors should treat this as a trigger to hunt for the gang's known pre-encryption TTPs — VPN edge-device exploitation, WMI/PsExec lateral movement, and staged exfiltration — using the detection content below.
Sourcing & Verification
- Corroboration status: 0 of 7 listings were independently observed by a second leak-site crawler. All 7 listings (AFRICA-TECH, FinSoft, Fanatics, Inter, PayPal support operations / Transcom WorldWide, Ministry of Education — Argentina, Argentem Creek Partners) appear on a single source only (ransomware.live aggregation).
- What a listing means: Inclusion on N0N's leak site reflects the threat actor's claim. It is NOT confirmation that a breach, intrusion, or data theft occurred. Criminal groups exaggerate, fabricate, and recycle claims for leverage and reputational effect.
- Denials and silence: A named organization may dispute the listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question. Only the organization itself or its regulator can confirm an incident.
- Corrections: Security Arsenal will publish corrections to this briefing as additional verification becomes available, and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — N0N
- Aliases: N0N (also stylized "N0N Ransomware" on its own infrastructure). No widely documented rebrand lineage has been established as of this writing.
- Operating model: Assessed as a Ransomware-as-a-Service (RaaS) operation with a core team maintaining the encryptor, negotiation portal, and leak site, while affiliates conduct intrusions. The geographic and sectoral spread of recent listings (Mali to Sweden, telecom to investment firms) is characteristic of affiliate-driven targeting rather than a single closed crew.
- Ransom demands: Observed demands in comparable mid-tier RaaS operations range from the low hundreds of thousands to several million USD, scaled to victim revenue. N0N typically opens with a demand calibrated to the victim's perceived ability to pay, then escalates via leak-site countdown timers.
- Initial access methods (typical):
- Exploitation of internet-facing VPN concentrators and firewall management planes (consistent with the KEV-listed edge CVEs discussed below)
- Phishing with macro-enabled documents or malicious attachments delivering loaders
- RDP brute force / purchased RDP credentials from access brokers
- Occasional supply-chain / developer-tooling compromise as an entry path
- Extortion model: Double extortion — data is staged and exfiltrated before encryption, then threatened for publication on the leak site if payment is refused. The listings in this briefing are the public-facing phase of that pressure cycle.
- Dwell time: Industry reporting on similar RaaS affiliates places median dwell time at 5–11 days from initial access to detonation, with exfiltration typically beginning 24–72 hours before encryption. The cluster of postings on 2026-09-18 suggests intrusions likely began in the first half of September, if the claims are genuine.
Current Campaign Analysis
Sectors Targeted (from observed listings)
| Sector | Listings | Named Organizations |
|---|---|---|
| Technology | 2 | AFRICA-TECH (ML), Inter (VE) |
| Retail & E-Commerce | 2 | FinSoft (UZ), Fanatics (US) |
| Financial Services | 2 | PayPal support operations / Transcom WorldWide (SE), Argentem Creek Partners (US) |
| Government & Defense | 1 | Ministry of Education — Argentina (AR) |
The sector mix shows no single-industry focus — this reads as opportunistic affiliate targeting driven by whatever initial access was available (purchased credentials, exploitable edge devices), not a strategic sector campaign. Notable inclusions: a large ISP (Inter, Venezuela's largest internet provider), a global sports commerce platform (Fanatics), and a government education ministry — targets chosen for pressure value, not technical specificity.
Geographic Concentration
Listings span ML, UZ, US, VE, SE, and AR. There is a deliberate-looking split between high-leverage US/EU names (Fanatics, Argentem Creek Partners, Transcom WorldWide's PayPal support operations) and emerging-market infrastructure and government (Mali, Uzbekistan, Venezuela, Argentina), where incident response maturity and regulatory disclosure regimes vary widely — a pattern that maximizes extortion pressure while minimizing law-enforcement friction.
Victim Profile
- Size range: Mid-market to large enterprise. Estimated revenues range from tens of millions USD (regional software and IT services firms like FinSoft, AFRICA-TECH) to billions (global commerce platforms and major ISPs).
- Common thread: Organizations with either (a) large volumes of PII/payment-adjacent data, or (b) operationally critical services where downtime creates negotiation leverage.
Posting Frequency / Escalation
- 7 postings in 5 days (2026-09-18 through 2026-09-22), with a cluster of four listings on 2026-09-18 followed by a pause and then three more on 09-20/09-22.
- This burst-pause-burst cadence is consistent with a single affiliate (or small set) working a batch of accesses and posting victims as negotiations stall. Watch for a second wave in the next 7–10 days as countdown timers expire.
Potential Initial Access Vectors (Hypothesis — CVE-Level Exposure)
Important: We have NO evidence linking any specific CVE to any specific named listing above. The following is sector-level exposure analysis only.
N0N's known preference for edge-device and remote-access exploitation aligns with several vulnerabilities currently in CISA's Known Exploited Vulnerabilities catalog with confirmed ransomware use:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Direct VPN-gateway compromise; the highest-priority hypothesis for a group with N0N's access patterns. Added to KEV 2026-06-08.
- CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane takeover of network security infrastructure. Added to KEV 2026-07-29.
- CVE-2026-59310 — Broadcom VMware vCenter path traversal. Post-access pivot to hypervisor management — enables mass encryption of virtualized estates, matching double-extortion playbooks. Added to KEV 2026-08-18.
- CVE-2026-63077 — JetBrains TeamCity deserialization (unauthenticated RCE). CI/CD server compromise; relevant to the technology-sector listings as a software supply-chain foothold. Added to KEV 2026-08-05.
- CVE-2026-48027 — Nx Console embedded malicious code. Developer-workstation supply-chain vector. Added to KEV 2026-05-27.
Defensive translation: If you operate Check Point gateways, Cisco FMC, vCenter, or TeamCity and are in a named sector, treat these four KEV entries as patch-by-yesterday items and hunt for exploitation artifacts retroactively to the KEV publication dates.
Detection Engineering
The following rules target N0N's observed playbook: edge/VPN initial access, WMI/PsExec lateral movement, pre-encryption data staging, and shadow-copy destruction. Tune thresholds to your environment before production deployment.
---
title: N0N Ransomware - PsExec-Style Remote Service Creation for Lateral Movement
id: 8f3a1c2e-7b4d-4e5a-9c1f-n0n000000001
status: experimental
description: Detects remote service creation consistent with PsExec/PAExec-style lateral movement used by N0N affiliates to deploy tooling and encryptors across hosts.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/23
logsource:
category: service_creation
product: windows
detection:
selection_service:
ServiceName|contains:
- 'PSEXESVC'
- 'PAExec'
- 'RemComSvc'
ImagePath|contains:
- '\\ADMIN$\\'
- '\\IPC$\\'
- '\Windows\PSEXESVC.exe'
filter_legit:
ServiceName|startswith: 'MsDeploy'
condition: selection_service and not filter_legit
fields:
- ServiceName
- ImagePath
- User
- ComputerName
falsepositives:
- Legitimate administrative remote management tools (SCCM, PDQ, Tanium)
level: high
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1569.002
- ttp.n0n-ransomware
---
title: N0N Ransomware - Pre-Encryption Data Staging via Archive Utilities
id: 8f3a1c2e-7b4d-4e5a-9c1f-n0n000000002
status: experimental
description: Detects execution of common archiving tools (rar, 7z, WinRAR) with password or high-compression flags on servers, consistent with N0N's pre-exfiltration data staging behavior.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/23
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\rar.exe'
- '\7z.exe'
- '\7za.exe'
- '\winrar.exe'
selection_flags:
CommandLine|contains:
- ' -p'
- ' -hp'
- ' -m5'
- ' a '
selection_scope:
CommandLine|contains:
- '\Users\\'
- '\Shares\\'
- '\\*'
filter_workstations:
ComputerName|contains: 'WKS-'
condition: selection_img and selection_flags and selection_scope and not filter_workstations
fields:
- CommandLine
- ParentImage
- User
- ComputerName
falsepositives:
- Backup scripts, software packaging on build servers
level: high
tags:
- attack.collection
- attack.t1560.001
- ttp.n0n-ransomware
---
title: N0N Ransomware - Shadow Copy Deletion and Backup Tampering
id: 8f3a1c2e-7b4d-4e5a-9c1f-n0n000000003
status: experimental
description: Detects Volume Shadow Copy deletion and backup catalog tampering, a hallmark pre-encryption step in N0N and peer RaaS operations.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/09/23
logsource:
category: process_creation
product: windows
detection:
selection_vss:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
- '\wbadmin.exe'
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'delete catalog'
- 'recoveryenabled no'
- 'Get-WmiObject Win32_Shadowcopy'
- 'Remove-WmiObject'
- 'resize shadowstorage'
condition: selection_vss
fields:
- CommandLine
- ParentCommandLine
- User
- ComputerName
falsepositives:
- Rare; some storage optimization scripts resize shadowstorage
level: critical
tags:
- attack.impact
- attack.t1490
- attack.defense_evasion
- ttp.n0n-ransomware
The KQL hunt below looks for the lateral-movement-to-staging sequence typical of N0N affiliates in the 72 hours before detonation: remote service creation or WMI execution followed by bulk file access and archive creation, aggregated per device and account.
// N0N pre-ransomware staging hunt: remote execution + bulk access + archiving on same host
// Microsoft Sentinel / Defender XDR — run over a 7-day window
let Lookback = 7d;
let RemoteExec =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName in~ ("psexec.exe","psexesvc.exe","paexec.exe","wmic.exe","wmiprvse.exe")
or (FileName =~ "services.exe" and ProcessCommandLine has "PSEXESVC")
| project RemoteTime=TimeGenerated, DeviceName, AccountName=InitiatingProcessAccountName,
RemoteTool=FileName, RemoteCmd=ProcessCommandLine, RemoteParent=InitiatingProcessFileName;
let Archiving =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName in~ ("rar.exe","7z.exe","7za.exe","winrar.exe")
| where ProcessCommandLine has_any (" -p", " -hp", " a ", " -m5")
| project ArchiveTime=TimeGenerated, DeviceName, AccountName=InitiatingProcessAccountName,
ArchiveCmd=ProcessCommandLine;
let BulkAccess =
DeviceFileEvents
| where TimeGenerated > ago(Lookback)
| where FileName endswith_any (".docx",".xlsx",".pdf",".csv",".sql",".bak",".zip",".pst")
| where ActionType == "FileCreated" or ActionType == "FileRenamed"
| summarize FileOps=count(), DistinctPaths=dcount(FolderPath)
by DeviceName, AccountName=InitiatingProcessAccountName, bin(TimeGenerated, 1h)
| where FileOps > 500;
RemoteExec
| join kind=inner Archiving on DeviceName
| where ArchiveTime between (RemoteTime .. RemoteTime + 48h)
| join kind=leftouter BulkAccess on DeviceName
| summarize FirstRemote=min(RemoteTime), FirstArchive=min(ArchiveTime),
Tools=make_set(RemoteTool), SampleCmds=make_set(ArchiveCmd, 5),
MaxFileOps=max_of(FileOps, 0)
by DeviceName, AccountName
| where MaxFileOps > 0 or array_length(Tools) > 0
| project DeviceName, AccountName, FirstRemote, FirstArchive, Tools, MaxFileOps, SampleCmds
| order by FirstRemote asc;
Rapid-response script: audit RDP exposure, recently created scheduled tasks, and shadow-copy state — the three fastest checks when a listing like N0N's lands in your sector.
<#
.SYNOPSIS
Security Arsenal - N0N rapid-response exposure audit
.DESCRIPTION
1) Flags internet-facing RDP listeners and non-standard RDP ports
2) Enumerates scheduled tasks created in the last 7 days (common N0N persistence)
3) Reports Volume Shadow Copy status and recent deletions (Event ID 36/22 style sources)
Run as Administrator on domain-joined Windows hosts. TLP:CLEAR.
#>
$Report = [ordered]@{ Host = $env:COMPUTERNAME; Time = (Get-Date).ToString('s') }
# --- 1) RDP exposure ---
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue).fDenyTSConnections -eq 0
$rdpPort = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -ErrorAction SilentlyContinue).PortNumber
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue).UserAuthentication
$Report.RDP_Enabled = $rdpEnabled
$Report.RDP_Port = $rdpPort
$Report.RDP_NLA_Enforced = ($nla -eq 1)
if ($rdpEnabled -and $nla -ne 1) { Write-Warning "RDP enabled WITHOUT NLA — brute-force exposure (N0N initial access vector)." }
if ($rdpPort -eq 3389) { Write-Host "[*] RDP on default port 3389 — verify it is NOT reachable from the internet (scan your external ranges)." }
# --- 2) Scheduled tasks created in the last 7 days ---
$since = (Get-Date).AddDays(-7)
$tasks = Get-ScheduledTask | ForEach-Object {
$info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
[PSCustomObject]@{ Name=$_.TaskName; Path=$_.TaskPath; Author=$_.Author;
Created=$info.LastRunTime; Action=($_.Actions | ForEach-Object { $_.Execute + ' ' + $_.Arguments }) -join ' | ' }
}
Write-Host "`n[+] Scheduled tasks (review for suspicious names/paths):`n"
$tasks | Where-Object { $_.Action -match 'powershell|cmd|wscript|rundll32|regsvr32|\\Temp\\|\\AppData\\' } |
Format-Table -AutoSize
# Tasks with suspicious action locations are higher-signal than creation-date metadata,
# which is not reliably exposed; hunt SIEM Event ID 4698/4702 for true creation time.
# --- 3) Shadow copy integrity ---
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
$Report.ShadowCopy_Count = @($shadows).Count
if (@($shadows).Count -eq 0) { Write-Warning "ZERO Volume Shadow Copies present — possible pre-encryption tampering (vssadmin delete shadows)." }
# Recent VSS deletion telemetry from System log (vssadmin/wmic deletions leave audit gaps;
# pair with the Sigma rule above and process creation logs)
$vssEvents = Get-WinEvent -FilterHashtable @{LogName='System'; Id=36,8229; StartTime=$since} -ErrorAction SilentlyContinue
$Report.VSS_Events_Last7d = @($vssEvents).Count
Write-Host "`n[+] Summary:`n"
[PSCustomObject]$Report | Format-List
Incident Response Priorities
T-minus Detection Checklist (before encryption fires)
N0N's playbook, like most double-extortion RaaS crews, follows a detectable sequence in the final 72 hours:
- New remote services or WMI activity on servers from a single admin account — especially outside change windows (Sigma rule 1 + KQL above).
- Archive utility execution on file servers or database hosts —
rar/7zwith password flags is a leading indicator of staging (Sigma rule 2). - Abnormal outbound transfer volume — sustained multi-GB uploads to consumer cloud storage, MEGA, or unfamiliar ASNs from server VLANs.
- EDR/AV tampering attempts — service stop attempts on security tooling,
Set-MpPreference -DisableRealtimeMonitoring, driver loads for BYOVD. vssadmin delete shadows,bcdedit ... recoveryenabled no,wbadmin delete catalog— the 5-minute warning before detonation (Sigma rule 3). Alert paging-level on this.- Mass file renames or entropy spikes — detonation has begun; shift from hunt to containment immediately.
Assets N0N Historically Prioritizes for Exfiltration
Based on the listing profile above, expect targeting of:
- Customer PII and payment-adjacent records (retail/e-commerce, financial services listings)
- Subscriber databases and network configuration (telecom/ISP listing — Inter)
- HR records, contracts, and financial statements (investment firm listing — Argentem Creek Partners)
- Citizen/student data and internal correspondence (government listing — Ministry of Education)
- Source code and client deliverables (IT services and software listings — AFRICA-TECH, FinSoft)
Prioritize DLP and egress monitoring on the systems holding these data classes first.
Containment Actions — Ordered by Urgency
- Isolate, don't power off. Network-isolate affected hosts (EDR containment or switch-level) to preserve volatile evidence while cutting C2 and spread.
- Kill the access path. Force-reset the involved accounts, disable suspicious VPN sessions, and block the source infrastructure at the edge.
- Rotate broadly. KRBTGT twice if domain compromise is suspected; rotate all local admin (LAPS) and service account credentials on touched segments.
- Protect backups now. Verify backup infrastructure is offline/immutable and was not reachable from the compromised identity context.
- Preserve evidence. Capture memory and triage images of patient zero before remediation wipes artifacts.
- Engage counsel and review disclosure obligations — especially for organizations named on leak sites, where regulatory clocks may already be relevant regardless of your internal verification status.
Hardening Recommendations
Immediate (24 hours)
- Patch or mitigate the KEV edge stack: Check Point Security Gateway (CVE-2026-50751), Cisco FMC (CVE-2026-20316), vCenter (CVE-2026-59310), TeamCity (CVE-2026-63077). If patching is blocked, apply vendor workarounds and isolate management interfaces from the internet entirely.
- Enforce phishing-resistant MFA on all remote access (VPN, RDP gateways, O365/Entra). N0N's access-broker supply chain is defeated by FIDO2, not SMS.
- Block or alert on archive utilities on servers —
rar.exe/7z.exehave almost no legitimate use on production file/database servers. - Verify shadow copies exist and are protected on critical servers; enable tamper protection on EDR.
- Deploy the Sigma rules and KQL query above to your SIEM and run the PowerShell audit on Tier-0/Tier-1 assets.
- Review external RDP exposure — there should be none. Put RDP behind VPN + MFA or remove it.
Short-Term (2 Weeks)
- Segment backup and management planes onto dedicated, hardened networks with no domain-identity overlap with production admin accounts.
- Implement egress filtering with allowlisting for server VLANs — servers should not initiate arbitrary internet uploads; this single control breaks most RaaS exfiltration.
- Deploy honeytokens (canary files/credentials) on file shares and in credential stores to get early, high-fidelity staging alerts.
- Move CI/CD infrastructure (TeamCity, Nx/dev tooling) behind identity-aware proxies and treat build servers as Tier-0 — the supply-chain CVEs above make developer infrastructure a primary target class.
- Establish a leak-site monitoring and response playbook so that if your organization is ever listed — verified or not — legal, comms, and IR activate in parallel rather than sequentially.
All victim listings in this briefing are unverified threat-actor claims. See Sourcing & Verification above. Security Arsenal will update this briefing as corroboration develops.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.