Ransomware Group n0n Has Targeted Global Infrastructure
The new cybercriminal group uses stolen credentials and backup destruction threats to extort organizations.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust that your organization has the necessary tools to prevent a ransomware data breach?
A ransomware collective identified as n0n has emerged, threatening to destroy victim backup systems to compel payment. The group employs double extortion tactics after gaining access to corporate networks via third-party infostealer malware.
Why it matters
By targeting the ability to recover data, n0n increases pressure on organizations that might otherwise rely on backups to avoid paying ransoms. This strategy highlights the evolving threat of ransomware actors who aim to cripple operational resilience.
The group primarily targets organizations in the US, Vietnam, Uzbekistan, Brazil, Sweden, and Luxembourg. Attackers utilize stolen credentials from infostealer malware to escalate privileges and stage data for double extortion.
The players
n0n
This is a ransomware group that uses double extortion and threats to destroy backups to coerce victims.
CyberXTron
This is a cybersecurity research organization that analyzes and tracks malicious threat actor activity.
The details
CyberXTron researchers revealed that n0n maintains a dedicated leak site to host stolen information from non-compliant victims. The attackers use countdown timers as a psychological tool to force organizations into meeting their financial demands.
Timeline
September 18, 2026: Researchers first identified activity from the n0n ransomware group.
September 22, 2026: The group's leak site listed over a dozen victims.
September 23, 2026: CyberXTron researchers published findings on the group.
The Tech Race
The emergence of n0n signals an aggressive expansion in the double extortion landscape where groups target backup integrity to bypass recovery efforts. This shift forces organizations to move beyond simple restoration strategies toward more robust, immutable storage architectures.
Employees and IT administrators should be aware that credential theft from common infostealer malware is a primary entry point for these attacks. Strengthening identity management and implementing multi-factor authentication are critical steps to preventing initial network access.
The takeaway
Organizations must prioritize the protection of backup infrastructure as aggressively as they defend primary networks. Regular audits of administrative access and monitoring for credential theft are essential to mitigating the risk of ransomware extortion.
Further reading
For more information on the evolving threat landscape, visit our Cybersecurity section.
Source note: This article includes information reported by Infosecurity Magazine.
Live Poll
Do you trust that your organization has the necessary tools to prevent a ransomware data breach?







