Security2 publishers2 min readPublished
New ransomware crew n0n threatens to destroy the backups of victims who refuse to pay
n0n, a ransomware crew first seen September 18, listed over a dozen victims in four days and threatens to wipe the backups of those who refuse to pay. Whether it can depends on what its escalated admin accounts reach.
The Watch · Security desk

What happened
- Countdown timers for some n0n victims have already run out, and data stolen from those organizations has been released.
- Financial services makes up 23% of n0n's victims, technology, retail and education 15% each, with healthcare, defense and professional services also hit.
- The US is the most common target, and n0n has also claimed victims in Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Backup consoles and storage that accept the same administrator logins as production face the full threat; offline copies held under separate credentials sit outside the chain CyberXTron describes.
- decision A victim holding an n0n demand has to verify its restore copies before it can judge the backup threat. If those copies are intact, the data leak is the group's remaining leverage.
- constraint MFA on every external login blocks the documented first step, because the entry depends on a harvested password working on its own.
CyberXTron describes the intrusions as a sequence. Credentials harvested by third-party infostealer malware get the operators into the network. They escalate to administrative tools, then use those tools to manipulate and stage data ahead of the demand [9]. The threat to encrypt or destroy backups and shadow copies comes at the end of that chain [4]. It applies to whatever the escalated accounts can log in to.
Infosecurity Magazine takes the expired countdown timers as a sign that some victims are choosing not to pay despite the destructive threat [8]. The damage the reports document is theft and release of data, the leak half of a double-extortion model [3][8]. Neither report says n0n has destroyed a victim's backups.
Both published accounts come from one research team. SC World's brief credits Infosecurity Magazine [12], and Infosecurity's report draws on CyberXTron's blog post of September 23 [1]. The sector percentages fit a total of 13 victims, three in financial services and two in each sector at 15% [14]. On that count, financial services is ahead of technology, retail and education by one organization [14].
CyberXTron said organizations "should treat n0n as an active and credible double-extortion threat requiring prompt attention to credential hygiene, access monitoring, and backup isolation" [10]. Infosecurity lists five controls: MFA on all external access points, less exposure of VPN, RDP and remote access interfaces, least-privilege access, segmentation around critical systems and sensitive data, and monitoring for lateral movement and privilege misuse [11]. Of those, least privilege and segmentation are the ones that bear on the backup threat [11].
According to Infosecurity, double extortion has become highly popular and highly effective among ransomware groups [16]. What n0n adds is naming the backups in the threat itself [4]. Its public record covers the five days between CyberXTron's first sighting and its blog post [15].
What to watch
- A confirmed n0n case in which backups were actually encrypted or deleted, and whether the backup system shared credentials with production.
- Independent research beyond CyberXTron publishing n0n indicators or linking the group to an existing ransomware operation.
- Whether the leak-site count grows past the first dozen and more countdown timers expire with data releases instead of payments.