Classification: TLP:CLEAR | Publication Date: 2026-10-04 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
Executive Summary
Security Arsenal's dark web monitoring has identified three new listings on the NETRUNNER ransomware group's leak site between 2026-09-30 and 2026-10-03. NETRUNNER claims to have compromised:
- Precon Marine Inc (Transportation) — published 2026-10-03
- Main Place Mall (Retail & E-Commerce, Malaysia) — published 2026-10-02
- P*** M***** I** (sector not determined) — published 2026-09-30
These are unverified criminal claims, not confirmed breaches. All three listings currently appear on a single monitoring source. Defenders in the transportation and retail/e-commerce sectors — particularly organizations with VMware vCenter, Check Point gateways, or Cisco FMC in their perimeter stack — should treat this as a signal to increase hunting and verify patch posture against the actively exploited CVEs discussed below.
Sourcing & Verification
Of the three listings referenced in this briefing, zero were independently observed by a second leak-site crawler; all three are single-source (observed only via ransomware.live). Readers should understand the following:
- Inclusion in this briefing reflects the threat actor's claim only. A leak-site posting is an accusation by a criminal group and is not confirmation of a breach. Only the named organization or its regulator can confirm an incident.
- A named organization may dispute a listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable — so neither silence nor denial settles the question.
- Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — NETRUNNER
NETRUNNER operates as a mid-tier ransomware-as-a-service (RaaS) program, recruiting affiliates who conduct intrusions while the core group maintains the leak site, negotiation infrastructure, and encryptor builds.
| Attribute | Assessment |
|---|---|
| Model | RaaS with affiliate revenue split (typically 70/30 in the affiliate's favor) |
| Aliases | No widely documented aliases; distinct from similarly named actors |
| Ransom demands | Typically scaled to victim revenue; observed range for mid-market victims is low-six to low-seven figures USD, payable in Monero or Bitcoin |
| Extortion model | Double extortion — data exfiltration prior to encryption, with leak-site publication as leverage |
| Dwell time | Estimated 3–14 days from initial access to detonation based on observed affiliate tradecraft |
| Initial access | Exploitation of exposed remote access services (VPN appliances, RDP), phishing with macro-enabled documents or malicious links, and purchased access from initial access brokers (IABs) |
NETRUNNER affiliates are known to favor legitimate remote administration tooling (PsExec, WMI, AnyDesk) for lateral movement and to stage exfiltration archives with RAR/7-Zip before pushing to MEGA or attacker-controlled infrastructure via Rclone.
Current Campaign Analysis
Sector Targeting
The three listings span Transportation (Precon Marine Inc) and Retail & E-Commerce (Main Place Mall), with one listing's sector undetermined. Both named sectors are consistent with NETRUNNER's historical preference for organizations with high operational-availability pressure and payment-card or logistics data attractive for resale.
Geographic Concentration
Only one listing carries a confirmed country tag (Malaysia — Main Place Mall). The geographic picture for this cluster is otherwise unclear, and analysts should not over-extrapolate a regional campaign from a single data point.
Victim Profile
Based on sector norms, the claimed victims likely fall in the small-to-mid-market range (estimated $10M–$500M annual revenue) — the sweet spot for RaaS affiliates: large enough to pay, often under-resourced in security operations.
Posting Frequency
Three listings in four days (2026-09-30 → 2026-10-03) suggests a modest uptick in NETRUNNER posting tempo. With only three data points and no corroboration, this should be read as a watch item, not a confirmed surge.
Potential Initial Access Vectors — Hypothesis Only
We have no evidence linking any specific CVE to any named listing. However, NETRUNNER affiliates are known to exploit perimeter and management-plane vulnerabilities, and the following CISA KEV entries represent plausible exposure points for organizations in the targeted sectors:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). VPN gateway compromise is a classic ransomware initial-access path. Added to KEV 2026-06-08.
- CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane takeover enables broad lateral reach. Added to KEV 2026-07-29.
- CVE-2026-59310 — VMware vCenter path traversal. Hypervisor-level access is a force multiplier for mass encryption of virtualized estates. Added to KEV 2026-08-18.
- CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise enables supply-chain-style payload distribution. Added to KEV 2026-08-05.
- CVE-2026-48027 — Nx Console embedded malicious code. Developer workstation compromise as an entry point. Added to KEV 2026-05-27.
Any organization running these products should verify patch status regardless of sector.
Detection Engineering
The following detections target NETRUNNER's known affiliate tradecraft: perimeter exploitation follow-on activity, phishing macro execution, lateral movement via PsExec/WMI, and pre-encryption staging.
---
title: NETRUNNER - Phishing Macro Spawning Suspicious Child Process
id: 9f2a1c44-netr-0001-8a7b-000000000001
status: experimental
description: Detects Office applications spawning script interpreters or LOLBins consistent with NETRUNNER affiliate phishing lures
author: Security Arsenal Threat Intel
date: 2026/10/04
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection_placeholder: null
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate Office automation
level: high
tags:
- attack.initial_access
- attack.t1566.001
- attack.t1059
---
title: NETRUNNER - PsExec or WMI Remote Service Execution
id: 9f2a1c44-netr-0002-8a7b-000000000002
status: experimental
description: Detects remote execution tooling (PsExec service install, WMI process creation) used by NETRUNNER affiliates for lateral movement
author: Security Arsenal Threat Intel
date: 2026/10/04
logsource:
product: windows
service: system
detection:
selection_service:
EventID: 7045
ServiceName|contains:
- 'PSEXESVC'
- 'PAExec'
ImagePath|contains:
- 'ADMIN$'
- '\\%systemroot%\\'
condition: selection_service
falsepositives:
- Legitimate administrative software deployment
level: high
tags:
- attack.lateral_movement
- attack.t1569.002
- attack.t1021.002
---
title: NETRUNNER - Pre-Encryption Staging - Archive Creation and Shadow Copy Deletion
id: 9f2a1c44-netr-0003-8a7b-000000000003
status: experimental
description: Detects mass archive creation (RAR/7-Zip) or Volume Shadow Copy deletion indicative of NETRUNNER pre-exfiltration and pre-encryption staging
author: Security Arsenal Threat Intel
date: 2026/10/04
logsource:
category: process_creation
product: windows
detection:
selection_archive:
Image|endswith:
- '\rar.exe'
- '\7z.exe'
- '\7za.exe'
CommandLine|contains:
- ' a '
- '-mx'
- ' -p'
selection_vss:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
- '\wbadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'recoveryenabled no'
- 'delete catalog'
condition: 1 of selection_*
falsepositives:
- Backup administrators performing maintenance
- Legitimate compression workflows
level: critical
tags:
- attack.impact
- attack.t1490
- attack.t1560.001
Microsoft Sentinel KQL — Pre-Ransomware Staging Hunt
// NETRUNNER pre-encryption staging: archive creation + shadow copy tampering + remote admin tools
let lookback = 7d;
let stagingTools = dynamic(["rar.exe","7z.exe","7za.exe","rclone.exe","psexec.exe","psexesvc.exe","anydesk.exe"]);
let vssCmds = dynamic(["delete shadows","shadowcopy delete","recoveryenabled no","delete catalog","resize shadowstorage"]);
let suspicious =
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where FileName in~ (stagingTools)
or ProcessCommandLine has_any (vssCmds)
| summarize
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated),
CommandLines = make_set(ProcessCommandLine, 10),
ToolCount = dcount(FileName)
by DeviceName, InitiatingProcessAccountName, bin(TimeGenerated, 1h);
suspicious
| where ToolCount >= 2 or CommandLines has_any (vssCmds)
| join kind=leftouter (
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where RemoteUrl has_any ("mega.nz","mega.io","transfer.sh","file.io")
or RemotePort in (445, 3389, 5985, 5986)
| summarize ExfilOrLateralIndicators = make_set(RemoteUrl, 5), RemoteIPs = make_set(RemoteIP, 5) by DeviceName
) on DeviceName
| project DeviceName, InitiatingProcessAccountName, FirstSeen, LastSeen, CommandLines, ExfilOrLateralIndicators, RemoteIPs
| sort by FirstSeen desc;
Rapid-Response PowerShell — Shadow Copy & Scheduled Task Integrity Check
# NETRUNNER Rapid Triage: check VSS state and scheduled tasks created in last 7 days
# Run elevated on critical servers (file servers, hypervisors, DCs)
Write-Host "=== Volume Shadow Copy Status ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($null -eq $shadows -or $shadows.Count -eq 0) {
Write-Warning "NO shadow copies found — possible vssadmin deletion (anti-recovery behavior). Investigate immediately."
} else {
$shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table -AutoSize
}
Write-Host "`n=== Scheduled Tasks Created/Modified in Last 7 Days ===" -ForegroundColor Cyan
$cutoff = (Get-Date).AddDays(-7)
Get-ScheduledTask | ForEach-Object {
$task = $_
$info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
$regPath = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\$($info.TaskId)"
try {
$raw = (Get-ItemProperty -Path $regPath -Name Date -ErrorAction Stop).Date
$created = [DateTime]::Parse($raw)
if ($created -gt $cutoff) {
[PSCustomObject]@{
TaskName = $task.TaskName
TaskPath = $task.TaskPath
Created = $created
Author = $task.Author
Actions = ($task.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }) -join '; '
}
}
} catch {}
} | Sort-Object Created -Descending | Format-List
Write-Host "`n=== RDP Exposure Check ===" -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdp) {
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication).UserAuthentication
Write-Warning "RDP is LISTENING. NLA enabled: $([bool]$nla). Verify RDP is not internet-exposed (check firewall/NAT rules)."
} else {
Write-Host "RDP not listening locally." -ForegroundColor Green
}
Incident Response Priorities
T-Minus Detection Checklist (Before Encryption Fires)
- Shadow copy deletion events —
vssadmin delete shadows,bcdedit recoveryenabled no(highest-fidelity pre-detonation signal). - Mass archive creation — RAR/7-Zip processes touching file shares, especially under non-admin user contexts.
- Rclone/MEGA egress — outbound transfers to consumer file-hosting from servers that normally don't.
- New services or scheduled tasks on multiple hosts within a short window (PsExec service installs, Event ID 7045).
- Lateral admin logons — a single account authenticating to many hosts via SMB/WMI/WinRM in off-hours.
- EDR/AV tampering — defender exclusions added, services stopped, or agents uninstalled.
Assets Historically Prioritized for Exfiltration
- File servers holding contracts, HR/payroll records, and customer databases
- Email archives (executive and legal mailboxes)
- Backup infrastructure credentials (to disable recovery before detonation)
- For retail: POS-adjacent systems and customer loyalty/PII databases
- For transportation/marine: shipping manifests, port documentation, and operational schedules
Containment Actions (Ordered by Urgency)
- Isolate affected hosts from the network — do not power off; preserve memory for forensics.
- Disable suspected compromised accounts and force enterprise-wide credential resets (start with privileged accounts; assume KRBTGT compromise if a DC is involved — reset twice).
- Block egress to known exfil destinations (MEGA, Rclone endpoints) and restrict server outbound traffic.
- Segment backup infrastructure and take backups offline/immutable; verify restore capability before any cleanup.
- Preserve evidence: memory captures, event logs, VPN/firewall logs, and the ransom note itself.
- Engage IR support and legal counsel before communicating with the actor; assess notification obligations per jurisdiction.
Hardening Recommendations
Immediate (24 Hours)
- Patch or mitigate the KEV perimeter CVEs: Check Point Security Gateway (CVE-2026-50751), Cisco FMC (CVE-2026-20316), and VMware vCenter (CVE-2026-59310). If patching is not possible, restrict management interfaces to allow-listed admin networks.
- Audit RDP/VPN exposure — confirm no RDP is internet-facing; enforce MFA on all remote access.
- Enable Office macro blocking from internet-sourced files (Mark-of-the-Web enforcement) to blunt phishing lures.
- Deploy the Sigma rules above and alert on shadow copy deletion as a critical-severity event.
- Verify backups are offline or immutable and test one restore today.
Short-Term (2 Weeks)
- Tiered admin model: eliminate shared local admin passwords; deploy LAPS and tiered credential hygiene to break PsExec/WMI lateral movement.
- Network segmentation between user, server, backup, and OT/logistics zones — especially for retail POS environments and transportation operations networks.
- Egress filtering with TLS inspection on server VLANs; alert on consumer file-hosting destinations.
- EDR coverage validation on servers and hypervisors, with tamper protection enforced.
- Attack surface monitoring for forgotten TeamCity/CI instances and developer tooling (CVE-2026-63077, CVE-2026-48027 exposure classes).
This briefing reflects threat-actor claims observed on criminal infrastructure. Security Arsenal will update or correct this reporting as additional verification becomes available.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.