Ransomware Group intelligence
N0n
ActiveTrack N0n with 12 published victims and 1 known leak locations in a single intelligence view.
Overview
N0n is tracked by Dark Eye as a ransomware group with 12 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 0 0.0%
- Pending 12 100.0%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 18h ago | nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion |
Top Activity Sectors (8)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue N0n, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: N0n executes malicious payloads through PowerShell scripts to stage ransomware components.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: N0n disables security tools by terminating antivirus processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: N0n deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: N0n uses file and directory discovery via PowerShell to enumerate critical data paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: N0n moves laterally through SMB shares using stolen credentials to access additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: N0n encrypts victim files using AES-256 encryption with custom ransomware binaries targeting business documents.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: N0n inhibits system recovery by corrupting restore points and disabling backup service processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: N0n performs internal defacement by replacing victim web content with ransom notices on accessible servers.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (12)
Search, filter and paginate the victim timeline for N0n. Showing 1–12 of 12.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | FinSoft (Kolibri retail back-office software) id33047 View details | Uzbekistan | IT | pending | ||
|
Retail software vendor / IT services · Uzbekistan | Client databases of 10+ retail chains (keddo, marc, lancaster, comf_rus, ek, cr, bas_at, bas_juk, bas_nov, bas_zar): sales, stock, pricing, financial records; Back-office platform and API service data | One client database publishes per day after the deadline, starting with keddo. Their clients will know exactly whose software failed them. | [ACTIVE: deadline 2026-09-25 01:06 UTC] |
||||||
| Ransomware | Fanatics (global sports commerce platform) id33003 View details | United States | Retail / E-commerce | pending | ||
|
Sports commerce / e-commerce · United States | Complete order history: 46,902 order files (108 GB) with customer personal data; Accounts-payable invoices of league and brand partners; Customer balances, bank transaction archive, customer tax exemption certificates; The fraud-prevention data set | Their cloud data estate is under our destructive control; deletion has begun. | [ACTIVE: deadline 2026-09-23 01:01 UTC] |
||||||
| Ransomware | Inter (Venezuela's largest internet provider) id32981 View details | Venezuela, Bolivarian Republic of | Telecommunications | pending | ||
|
Telecommunications / ISP · Venezuela | Subscriber connection records: 15,300,000+ entries, tens of thousands of subscriber addresses with the services they contacted; Complete internal network map across all regional operations; Core infrastructure configuration evidence | Network traffic remains severed until settlement. | [ACTIVE: deadline 2026-09-20 18:39 UTC] |
||||||
| Ransomware | PayPal support operations (Transcom WorldWide) id32971 View details | Sweden | Telecommunications | pending | ||
|
Outsourced customer support / financial services · Netherlands / Tunisia | 86.7M connection records: daily support-agent sessions into PayPal corporate Citrix/AAA systems; Complete infrastructure map: internal AD, PKI, Netskope/Zscaler tenants, all 8 sites | All 8 sites are enforcing a network blackout until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC] |
||||||
| Ransomware | Ministry of Education — Argentina id32972 View details | Argentina | Public Sector | pending | ||
|
Government / education · Argentina | Complete network-security configuration of the ministry network; 1.08M connection records: national library (BNM), school-book selection platform, scholarship systems (becasprogresar), titulosvalidez, certificadosinfd, sitrared; Evidence of the Monero cryptocurrency miner operating inside the ministry network | The ministry network is under a total blackout until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC] |
||||||
| Ransomware | Argentem Creek Partners (investment firm) id32973 View details | United States | Services | pending | ||
|
Investment management / private credit · United States | Full corporate network evidence: 2.5M+ connection records, complete internal systems map (Active Directory, SharePoint, MSP tooling, office-security integrations); Tax-season document flows of the firm and its investor document delivery platform | Corporate connectivity remains severed until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC] |
||||||
| Ransomware | AstraZeneca Türkiye id32974 View details | Türkiye | Healthcare / Pharma | pending | ||
|
Pharmaceutical manufacturing (GxP) · Türkiye | Complete internal network-security configuration of all 3 sites (940 MB): every rule, device definition, remote-access mappings; 1.35M connection records: M365/Intune, SAP Concur, UniFi camera estate, internal applications | All sites are enforcing a total network blackout until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC] |
||||||
| Ransomware | STOKR (digital securities platform) id32975 View details | Luxembourg | IT | pending | ||
|
Digital securities / investment platform · Luxembourg - EU | KYC investor register: full names, emails, countries, nationalities, wallet addresses and tax IDs where present; Identity-to-crypto-wallet mapping of KYC-accepted investors (FR, DE, CH, BE, NL, UK and others); Internal platform admin directory with staff accounts and roles | The investor data will also be delivered to the tax authorities of the investors' countries. | [ACTIVE: deadline 2026-09-20 22:40 UTC] |
||||||
| Ransomware | Konnatus (usucapião legal services) id32976 View details | Brazil | Finance / Legal / Insurance | pending | ||
|
Legal services / real estate · Brazil | The application database: chart of accounts, income/outflow structures, account types; User accounts with password hashes | Publication proceeds after the deadline. | [ACTIVE: deadline 2026-09-20 03:32 UTC] |
||||||
| Ransomware | BeLi Teacher / FSC education centers (AWS) id32977 View details | Viet Nam | Services | pending | ||
|
Education / edtech · Vietnam | The complete CRM lead database: 152,044 contact records — names, emails, +84 phone numbers, cities, study interests, engagement history; The CRM file archive (tasks, forums, comments, customer files) migrated from GetFly CRM | Publication proceeds in batches after the deadline. | [ACTIVE: deadline 2026-09-20 02:47 UTC] |
||||||
| Ransomware | Vietnamese betting operator (GC789 network / Boundless TE) id32978 View details | Viet Nam | Finance / Legal / Insurance | pending | ||
|
Online gambling / agent platform · Vietnam / Switzerland | The complete bettor database: 2,021,011 registered bettors with names, +84 phone numbers, email addresses, deposit and withdrawal amounts; The full agent network: 39,998 agent accounts, hierarchy, balances, credit lines and commission ladders; 85 million login records with IP addresses and device identifiers; Daily trading and P&L data per provider; The fraud stack: 33,000+ blacklisted emails and phones, arbitrage and odds-mover reports, multi-account detection rules | Publication proceeds in batches after the deadline. | [ACTIVE: deadline 2026-09-20 01:37 UTC] |
||||||
| Ransomware | United Federation of Teachers id32979 View details | United States | NGOs / Associations | pending | ||
|
Education / Labor Union · US — New York | The union’s complete legal case archive — approx. 181,420 documents: grievance and arbitration files, disciplinary appeal decisions and personnel case files, each named for a member; Contract documents: CBAs, MOUs, MOAs and side letters; Nurse-federation and health-benefit-fund case materials; Teacher evaluation and class-size complaint files; Staff search and case-view audit logs | Publication proceeds in batches after the deadline. The victim can verify everything and settle in their private negotiation room. | [ACTIVE: deadline 2026-09-19 14:58 UTC] |
||||||