Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Gang n0n Threatens Backup Destruction to Press Victims

Empty server racks and storage units in a brightly-lit data center with scattered computer equipment on the floor.

“Organizations should treat n0n as an active and credible double-extortion threat requiring prompt attention to credential hygiene, access monitoring, and backup isolation,” CyberXTron warned in its September 23 blog post.

n0n's Backup-Destruction Threat

A newly formed ransomware crew calling itself n0n has added a direct threat to destroy or encrypt backup systems and shadow copies to the extortion playbook, according to researchers at CyberXTron. That tactic is intended to create fear that a compromised organization will be unable to recover its network at all unless it pays the ransom demand.

Double-Extortion and Tor Leak Site Activity

CyberXTron said n0n operates on a double-extortion model. The group began attracting attention after activity was first spotted on September 18 and, by September 22, had published information about more than a dozen victims on a Tor-hosted leak site. The countdown timers associated with some victims “have already reached zero and data stolen in the attacks has been released,” the researchers reported—indicating that at least some targets declined to pay and had their stolen data published.

Initial Access: Stolen Credentials and Infostealers

Analysts who reviewed confirmed incidents found a consistent initial access pattern: compromised credentials obtained via third-party infostealer malware. Those stolen credentials were used to gain entry to corporate environments, after which attackers escalated privileges and leveraged administrative tools to manipulate and stage data ahead of extortion demands.

Sector and Geographic Targeting

So far, the most frequently targeted sector is financial services, accounting for 23% of confirmed n0n victims. Technology, retail and education each represent 15% of victims, while organizations in healthcare, defense and professional services have also been targeted. Geographically, the United States is the most common target; n0n has also claimed victims in Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg.

Recommended Defenses from CyberXTron

  • Enforce multi-factor authentication (MFA) across all external access points
  • Restrict exposure of internet-facing services such as VPN, RDP, and remote access interfaces
  • Implement strict least-privilege access controls across all systems
  • Segment networks to isolate critical systems and sensitive data environments
  • Monitor internal access behavior for signs of unauthorized lateral movement or privilege misuse

What this means for technologists, affected enterprises, and the general public

  • Technologists and security teams should prioritize the exact controls CyberXTron named—credential hygiene, access monitoring, backup isolation and MFA—because n0n’s entry path relies on stolen credentials and its pressure point is backups and shadow copies.
  • Affected enterprises, especially financial services organizations (23% of known victims), will need to reassess the resilience of their recovery plans: backups that are reachable from compromised administrative accounts may no longer be a reliable safety net if attackers threaten or act to destroy them.
  • The general public should note that n0n has claimed victims across multiple countries and that, in some cases, stolen data has been released after ransom countdowns lapsed—meaning data exposure, not just operational disruption, is part of this group's modus operandi.

n0n’s combination of credential-driven access, privilege escalation and explicit backup-destruction threats raises a stark choice for targeted organizations: harden the front doors and internal controls that n0n exploits, or face the possibility that a post-compromise recovery option could be removed entirely. CyberXTron’s warning—treat n0n as an active and credible double-extortion threat—frames the immediate challenge: operational resilience now depends as much on isolating and protecting backups as it does on preventing initial access.

Source: https://www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/