Ransomware · 6h ago
CyberXTron said the new n0n ransomware gang first appeared on September 18 and had posted more than a dozen victims by September 22, using double extortion plus explicit threats to encrypt or destroy backups and shadow copies. The group’s leak site and ransom notes frame recovery itself as the ransom lever.
The tactic matters because it targets the copies organizations expect to restore from, not just the live systems they are extorting. If backups or shadow copies are online and reachable from the same environment, an attacker who gets in can make restoration slow, partial, or impossible even after encryption is cleared.
That shifts the risk from downtime plus data theft toward possible operational shutdown, especially for teams whose backup systems sit inside the production trust zone. The reporting does not show every victim’s recovery setup, but it does show an active campaign turning recovery infrastructure into attacker leverage.
1 source covering this story
Emerging Ransomware Gang Uses Backup Destruction Threats
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims
Part of the PlainSec briefing for 2026-09-24