# What happened Researchers at CyberXTron reported a newly observed ransomware crew calling itself n0n. The group was first spotted on September 18, 2026. By September 22 its Tor-hosted leak site showed information on more than a dozen victims. CyberXTron published a blog about the activity on September 23.
n0n uses a double-extortion approach: attackers steal sensitive corporate data and threaten publication unless a ransom is paid. The group takes that model further by explicitly threatening to encrypt or destroy backups and shadow copies, aiming to remove the victim's ability to recover without paying.
# How n0n gains access and operates Attackers appear to start with compromised credentials harvested by third-party infostealer malware. Those credentials provide initial access to corporate networks. From there the intruders escalate privileges and take control of administrative tools to move laterally, stage data exfiltration and prepare the environment for extortion.
The group also applies psychological pressure with countdown timers on leak pages. Some timers reached zero and the attackers released stolen data, demonstrating they will publish data if demands are not met.
# Who's being targeted
- Geography: the United States is the most common target, but n0n has claimed victims in Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg.
# Why the backup threat matters Threatening to encrypt or destroy backups and shadow copies changes the victim calculus. Even well-prepared organizations that maintain backups face the risk that those recovery points will be damaged or rendered unusable. That threat increases operational disruption and can force organizations to consider paying to regain access to both primary systems and backups.
# Concrete defensive steps CyberXTron recommends immediate attention to credential hygiene, access monitoring and backup isolation. Specific actions include:
- Enforce multi-factor authentication for all external and high-privilege access.
- Reduce exposure of internet-facing services such as VPN, RDP and other remote access interfaces.
- Apply strict least-privilege controls across user and service accounts.
- Monitor internal access behavior to detect unusual lateral movement or privilege misuse.
# What this signals for defenders n0n's approach combines credential-based access with deliberate preparation to neutralize recovery options. That sequence—credential theft, privilege escalation, admin-tool misuse, data staging, backup tampering threats—creates a compound risk beyond simple file encryption. Organizations should prioritize hardening of identity and access controls, restrict management interfaces, and treat backup isolation as a high-priority control.
# Short takeaway Treat n0n as an active double-extortion threat that explicitly targets recovery capability. Focus on credential protection, reduced external exposure, least privilege, segmentation and physical and logical isolation of backups to reduce the chance of catastrophic recovery loss.