A new ransomware group, dubbed n0n, has emerged with a dangerous tactic of threatening to destroy victim backups if ransom demands are not met, according to a recent report by Infosecurity Magazine.Researchers at CyberXTron first observed n0n activity on September 18, with the group quickly establishing a Tor-hosted leak site and claiming over a dozen victims by September 22. Operating on a double extortion model, n0n not only steals sensitive data but also explicitly threatens to encrypt or destroy backups and shadow copies. This tactic aims to instill fear, suggesting victims will have no recovery options if they don't pay. The financial services industry is the most targeted sector, accounting for 23% of victims, followed by technology, retail, and education at 15% each. While the US is the primary target, n0n has claimed victims globally.Initial access is gained through compromised credentials from infostealer malware, followed by privilege escalation to administrative tools. CyberXTron advises organizations to prioritize credential hygiene, access monitoring, and backup isolation to counter this threat.Source: Infosecurity Magazine
Ransomware
New ransomware group n0n escalates threats by targeting backups
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
