The newly observed n0n ransomware group is conducting double-extortion attacks that pair data theft with threats to encrypt or destroy victims' backups and shadow copies if ransom demands are not met. First identified by CyberXTron on September 18, the group had launched a Tor-based leak site and listed more than a dozen alleged victims by September 22; some countdowns expired with stolen data subsequently released.
n0n reportedly gains initial access through credentials stolen by third-party infostealer malware, escalates privileges, and abuses administrative access to prepare systems and data for extortion. Financial-services organizations are its primary targets, particularly in the United States, though reported victims also span technology, retail, education, healthcare, defense, and professional-services sectors worldwide. Organizations should prioritize credential hygiene, monitor privileged-access activity, and maintain isolated, protected backups.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
CyberXTron published details describing n0n's use of credentials stolen by infostealer malware for initial access, followed by privilege escalation and administrative access to stage victim data for extortion.
By this date, n0n had established a Tor-hosted leak site and listed more than a dozen alleged victims. The group threatened to release stolen data and to encrypt or destroy backups and shadow copies if ransoms were unpaid.
CyberXTron first observed activity from the newly emerged n0n ransomware group, which operates a double-extortion scheme.
Some victim countdown timers on n0n's leak site expired and stolen data was released, indicating that at least some victims did not pay the ransom.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.