Back to Intelligence

NETRUNNER Ransomware Gang: 3 New Leak-Site Listings — Transportation & Retail Targeting Analysis with Detection Rules

SA
Security Arsenal Team
October 3, 2026
10 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-04 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

Executive Summary

Security Arsenal's dark web monitoring has identified three new listings on the NETRUNNER ransomware group's leak site between 2026-09-30 and 2026-10-03. NETRUNNER claims to have compromised:

  • Precon Marine Inc (Transportation) — published 2026-10-03
  • Main Place Mall (Retail & E-Commerce, Malaysia) — published 2026-10-02
  • P*** M***** I** (sector not determined) — published 2026-09-30

These are unverified criminal claims, not confirmed breaches. All three listings currently appear on a single monitoring source. Defenders in the transportation and retail/e-commerce sectors — particularly organizations with VMware vCenter, Check Point gateways, or Cisco FMC in their perimeter stack — should treat this as a signal to increase hunting and verify patch posture against the actively exploited CVEs discussed below.

Sourcing & Verification

Of the three listings referenced in this briefing, zero were independently observed by a second leak-site crawler; all three are single-source (observed only via ransomware.live). Readers should understand the following:

  • Inclusion in this briefing reflects the threat actor's claim only. A leak-site posting is an accusation by a criminal group and is not confirmation of a breach. Only the named organization or its regulator can confirm an incident.
  • A named organization may dispute a listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable — so neither silence nor denial settles the question.
  • Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — NETRUNNER

NETRUNNER operates as a mid-tier ransomware-as-a-service (RaaS) program, recruiting affiliates who conduct intrusions while the core group maintains the leak site, negotiation infrastructure, and encryptor builds.

AttributeAssessment
ModelRaaS with affiliate revenue split (typically 70/30 in the affiliate's favor)
AliasesNo widely documented aliases; distinct from similarly named actors
Ransom demandsTypically scaled to victim revenue; observed range for mid-market victims is low-six to low-seven figures USD, payable in Monero or Bitcoin
Extortion modelDouble extortion — data exfiltration prior to encryption, with leak-site publication as leverage
Dwell timeEstimated 3–14 days from initial access to detonation based on observed affiliate tradecraft
Initial accessExploitation of exposed remote access services (VPN appliances, RDP), phishing with macro-enabled documents or malicious links, and purchased access from initial access brokers (IABs)

NETRUNNER affiliates are known to favor legitimate remote administration tooling (PsExec, WMI, AnyDesk) for lateral movement and to stage exfiltration archives with RAR/7-Zip before pushing to MEGA or attacker-controlled infrastructure via Rclone.

Current Campaign Analysis

Sector Targeting

The three listings span Transportation (Precon Marine Inc) and Retail & E-Commerce (Main Place Mall), with one listing's sector undetermined. Both named sectors are consistent with NETRUNNER's historical preference for organizations with high operational-availability pressure and payment-card or logistics data attractive for resale.

Geographic Concentration

Only one listing carries a confirmed country tag (Malaysia — Main Place Mall). The geographic picture for this cluster is otherwise unclear, and analysts should not over-extrapolate a regional campaign from a single data point.

Victim Profile

Based on sector norms, the claimed victims likely fall in the small-to-mid-market range (estimated $10M–$500M annual revenue) — the sweet spot for RaaS affiliates: large enough to pay, often under-resourced in security operations.

Posting Frequency

Three listings in four days (2026-09-30 → 2026-10-03) suggests a modest uptick in NETRUNNER posting tempo. With only three data points and no corroboration, this should be read as a watch item, not a confirmed surge.

Potential Initial Access Vectors — Hypothesis Only

We have no evidence linking any specific CVE to any named listing. However, NETRUNNER affiliates are known to exploit perimeter and management-plane vulnerabilities, and the following CISA KEV entries represent plausible exposure points for organizations in the targeted sectors:

  • CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). VPN gateway compromise is a classic ransomware initial-access path. Added to KEV 2026-06-08.
  • CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane takeover enables broad lateral reach. Added to KEV 2026-07-29.
  • CVE-2026-59310 — VMware vCenter path traversal. Hypervisor-level access is a force multiplier for mass encryption of virtualized estates. Added to KEV 2026-08-18.
  • CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise enables supply-chain-style payload distribution. Added to KEV 2026-08-05.
  • CVE-2026-48027 — Nx Console embedded malicious code. Developer workstation compromise as an entry point. Added to KEV 2026-05-27.

Any organization running these products should verify patch status regardless of sector.

Detection Engineering

The following detections target NETRUNNER's known affiliate tradecraft: perimeter exploitation follow-on activity, phishing macro execution, lateral movement via PsExec/WMI, and pre-encryption staging.

YAML
---
title: NETRUNNER - Phishing Macro Spawning Suspicious Child Process
id: 9f2a1c44-netr-0001-8a7b-000000000001
status: experimental
description: Detects Office applications spawning script interpreters or LOLBins consistent with NETRUNNER affiliate phishing lures
author: Security Arsenal Threat Intel
date: 2026/10/04
references:
    - https://securityarsenal.com/darkside
logsource:
    category: process_creation
    product: windows
 detection_placeholder: null
detection:
    selection_parent:
        ParentImage|endswith:
            - '\winword.exe'
            - '\excel.exe'
            - '\powerpnt.exe'
            - '\outlook.exe'
    selection_child:
        Image|endswith:
            - '\powershell.exe'
            - '\pwsh.exe'
            - '\wscript.exe'
            - '\cscript.exe'
            - '\mshta.exe'
            - '\rundll32.exe'
            - '\certutil.exe'
            - '\bitsadmin.exe'
    condition: selection_parent and selection_child
falsepositives:
    - Rare legitimate Office automation
level: high
tags:
    - attack.initial_access
    - attack.t1566.001
    - attack.t1059
---
title: NETRUNNER - PsExec or WMI Remote Service Execution
id: 9f2a1c44-netr-0002-8a7b-000000000002
status: experimental
description: Detects remote execution tooling (PsExec service install, WMI process creation) used by NETRUNNER affiliates for lateral movement
author: Security Arsenal Threat Intel
date: 2026/10/04
logsource:
    product: windows
    service: system
detection:
    selection_service:
        EventID: 7045
        ServiceName|contains:
            - 'PSEXESVC'
            - 'PAExec'
        ImagePath|contains:
            - 'ADMIN$'
            - '\\%systemroot%\\'
    condition: selection_service
falsepositives:
    - Legitimate administrative software deployment
level: high
tags:
    - attack.lateral_movement
    - attack.t1569.002
    - attack.t1021.002
---
title: NETRUNNER - Pre-Encryption Staging - Archive Creation and Shadow Copy Deletion
id: 9f2a1c44-netr-0003-8a7b-000000000003
status: experimental
description: Detects mass archive creation (RAR/7-Zip) or Volume Shadow Copy deletion indicative of NETRUNNER pre-exfiltration and pre-encryption staging
author: Security Arsenal Threat Intel
date: 2026/10/04
logsource:
    category: process_creation
    product: windows
detection:
    selection_archive:
        Image|endswith:
            - '\rar.exe'
            - '\7z.exe'
            - '\7za.exe'
        CommandLine|contains:
            - ' a '
            - '-mx'
            - ' -p'
    selection_vss:
        Image|endswith:
            - '\vssadmin.exe'
            - '\wmic.exe'
            - '\bcdedit.exe'
            - '\wbadmin.exe'
        CommandLine|contains:
            - 'delete shadows'
            - 'shadowcopy delete'
            - 'recoveryenabled no'
            - 'delete catalog'
    condition: 1 of selection_*
falsepositives:
    - Backup administrators performing maintenance
    - Legitimate compression workflows
level: critical
tags:
    - attack.impact
    - attack.t1490
    - attack.t1560.001

Microsoft Sentinel KQL — Pre-Ransomware Staging Hunt

KQL — Microsoft Sentinel / Defender
// NETRUNNER pre-encryption staging: archive creation + shadow copy tampering + remote admin tools
let lookback = 7d;
let stagingTools = dynamic(["rar.exe","7z.exe","7za.exe","rclone.exe","psexec.exe","psexesvc.exe","anydesk.exe"]);
let vssCmds = dynamic(["delete shadows","shadowcopy delete","recoveryenabled no","delete catalog","resize shadowstorage"]);
let suspicious =
    DeviceProcessEvents
    | where TimeGenerated > ago(lookback)
    | where FileName in~ (stagingTools)
       or ProcessCommandLine has_any (vssCmds)
    | summarize
        FirstSeen = min(TimeGenerated),
        LastSeen = max(TimeGenerated),
        CommandLines = make_set(ProcessCommandLine, 10),
        ToolCount = dcount(FileName)
        by DeviceName, InitiatingProcessAccountName, bin(TimeGenerated, 1h);
suspicious
| where ToolCount >= 2 or CommandLines has_any (vssCmds)
| join kind=leftouter (
    DeviceNetworkEvents
    | where TimeGenerated > ago(lookback)
    | where RemoteUrl has_any ("mega.nz","mega.io","transfer.sh","file.io")
       or RemotePort in (445, 3389, 5985, 5986)
    | summarize ExfilOrLateralIndicators = make_set(RemoteUrl, 5), RemoteIPs = make_set(RemoteIP, 5) by DeviceName
) on DeviceName
| project DeviceName, InitiatingProcessAccountName, FirstSeen, LastSeen, CommandLines, ExfilOrLateralIndicators, RemoteIPs
| sort by FirstSeen desc;

Rapid-Response PowerShell — Shadow Copy & Scheduled Task Integrity Check

PowerShell
# NETRUNNER Rapid Triage: check VSS state and scheduled tasks created in last 7 days
# Run elevated on critical servers (file servers, hypervisors, DCs)

Write-Host "=== Volume Shadow Copy Status ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($null -eq $shadows -or $shadows.Count -eq 0) {
    Write-Warning "NO shadow copies found — possible vssadmin deletion (anti-recovery behavior). Investigate immediately."
} else {
    $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table -AutoSize
}

Write-Host "`n=== Scheduled Tasks Created/Modified in Last 7 Days ===" -ForegroundColor Cyan
$cutoff = (Get-Date).AddDays(-7)
Get-ScheduledTask | ForEach-Object {
    $task = $_
    $info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
    $regPath = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\$($info.TaskId)"
    try {
        $raw = (Get-ItemProperty -Path $regPath -Name Date -ErrorAction Stop).Date
        $created = [DateTime]::Parse($raw)
        if ($created -gt $cutoff) {
            [PSCustomObject]@{
                TaskName   = $task.TaskName
                TaskPath   = $task.TaskPath
                Created    = $created
                Author     = $task.Author
                Actions    = ($task.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }) -join '; '
            }
        }
    } catch {}
} | Sort-Object Created -Descending | Format-List

Write-Host "`n=== RDP Exposure Check ===" -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdp) {
    $nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication).UserAuthentication
    Write-Warning "RDP is LISTENING. NLA enabled: $([bool]$nla). Verify RDP is not internet-exposed (check firewall/NAT rules)."
} else {
    Write-Host "RDP not listening locally." -ForegroundColor Green
}

Incident Response Priorities

T-Minus Detection Checklist (Before Encryption Fires)

  1. Shadow copy deletion events — vssadmin delete shadows, bcdedit recoveryenabled no (highest-fidelity pre-detonation signal).
  2. Mass archive creation — RAR/7-Zip processes touching file shares, especially under non-admin user contexts.
  3. Rclone/MEGA egress — outbound transfers to consumer file-hosting from servers that normally don't.
  4. New services or scheduled tasks on multiple hosts within a short window (PsExec service installs, Event ID 7045).
  5. Lateral admin logons — a single account authenticating to many hosts via SMB/WMI/WinRM in off-hours.
  6. EDR/AV tampering — defender exclusions added, services stopped, or agents uninstalled.

Assets Historically Prioritized for Exfiltration

  • File servers holding contracts, HR/payroll records, and customer databases
  • Email archives (executive and legal mailboxes)
  • Backup infrastructure credentials (to disable recovery before detonation)
  • For retail: POS-adjacent systems and customer loyalty/PII databases
  • For transportation/marine: shipping manifests, port documentation, and operational schedules

Containment Actions (Ordered by Urgency)

  1. Isolate affected hosts from the network — do not power off; preserve memory for forensics.
  2. Disable suspected compromised accounts and force enterprise-wide credential resets (start with privileged accounts; assume KRBTGT compromise if a DC is involved — reset twice).
  3. Block egress to known exfil destinations (MEGA, Rclone endpoints) and restrict server outbound traffic.
  4. Segment backup infrastructure and take backups offline/immutable; verify restore capability before any cleanup.
  5. Preserve evidence: memory captures, event logs, VPN/firewall logs, and the ransom note itself.
  6. Engage IR support and legal counsel before communicating with the actor; assess notification obligations per jurisdiction.

Hardening Recommendations

Immediate (24 Hours)

  • Patch or mitigate the KEV perimeter CVEs: Check Point Security Gateway (CVE-2026-50751), Cisco FMC (CVE-2026-20316), and VMware vCenter (CVE-2026-59310). If patching is not possible, restrict management interfaces to allow-listed admin networks.
  • Audit RDP/VPN exposure — confirm no RDP is internet-facing; enforce MFA on all remote access.
  • Enable Office macro blocking from internet-sourced files (Mark-of-the-Web enforcement) to blunt phishing lures.
  • Deploy the Sigma rules above and alert on shadow copy deletion as a critical-severity event.
  • Verify backups are offline or immutable and test one restore today.

Short-Term (2 Weeks)

  • Tiered admin model: eliminate shared local admin passwords; deploy LAPS and tiered credential hygiene to break PsExec/WMI lateral movement.
  • Network segmentation between user, server, backup, and OT/logistics zones — especially for retail POS environments and transportation operations networks.
  • Egress filtering with TLS inspection on server VLANs; alert on consumer file-hosting destinations.
  • EDR coverage validation on servers and hypervisors, with tamper protection enforced.
  • Attack surface monitoring for forgotten TeamCity/CI instances and developer tooling (CVE-2026-63077, CVE-2026-48027 exposure classes).

This briefing reflects threat-actor claims observed on criminal infrastructure. Security Arsenal will update or correct this reporting as additional verification becomes available.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.