Ransomware Group intelligence
Netrunner
InactiveTrack Netrunner with 6 published victims and 1 known leak locations in a single intelligence view.
Overview
Netrunner is tracked by Breach House as a ransomware group with 6 published victims.
Japan is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 2 66.7%
- Pending 1 33.3%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 3h ago | netrunrsb3bivj5gnwajzxlig5qkteb6edgthxj7fmsvhkzxtwfxwaad.onion |
Top Activity Sectors (3)
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Netrunner, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: netrunner executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: netrunner modifies registry run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: netrunner disables antivirus tools and security software via command-line utilities to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: netrunner deletes Volume Shadow Copies and backup directories via vssadmin to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: netrunner scans network shares using SMB tools to identify valuable files across victim infrastructure.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: netrunner exploits SMB/Windows Admin Shares to move laterally between engineering workstations in Japan.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: netrunner exfiltrates stolen patient records and engineering designs over encrypted C2 channels before encryption.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: netrunner encrypts critical manufacturing and healthcare data using custom ransomware binaries for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: netrunner triggers system shutdown commands and service termination to maximize operational disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[rand].README.txt
You Have Been Breached By The NetRunner Team We See You Noticed The Strange Egress Traffic From Your Network, That's Us Uploading 960GB Of Your Sensitive And Compromising Data To Our Servers Data Includes: - Complete Schema, Drawing, Design, Spec, BOM, Issue And Complaint Related To KIA, Hyundai - Financial Information Including Bank Statement, Audit, Invoice, Budget, Sale, Annual Report, Agreement And Tax Issue - Employees PII, CV, Medical Record And More ...... If You Refuse To Contact Us Or We Do Not Come To An Agreement, YOUR DATA WILL BE PUBLISHED >>>> How To Contact Us 1. Download And Install qTox Anonymous Chat From The Official Website https://tox.chat/download.html 2. Add 02B37A5C56F8A4A73284B3CF5972D6F5C92258EC0B6269DF5C64E364E8AA8C0B0C51D7B87747 To Your Contact List, This Is The Fastest Way To Contact Us * If You Did Not Hear From Us Within 24 hours, Send Us An Email At [email protected] >>>> Visit Our Blog And See File Samples 1. Download And Install Tor Browser From https://www.torproject.org/download/ 2. Go To Your Private View Link MAIN http://netrunnlekx5rsfc7l3k3wbczr5m7rbdlgmf6aeyvgo5rsakki6ljjqd.onion/privateview/[snip] MIRROR http://netrunrsb3bivj5gnwajzxlig5qkteb6edgthxj7fmsvhkzxtwfxwaad.onion/privateview/[snip] >>>> Your personal DECRYPTION ID: [snip] >>>> Warning! Do not DELETE or MODIFY any files, it can lead to recovery problems!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (6)
Search, filter and paginate the victim timeline for Netrunner. Showing 1–6 of 6.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Jordan India Fertilizer Company id27873 View details | Jordan | Manufacturing / Engineering | leaked | ||
|
Indian Farmers Fertiliser Cooperative (IFFCO) and Jordan Phosphates Mines Company Ltd (JPMC) had formed a Limited Liability Joint Venture Company, namely Jordan India Fertiliser Company (JIFCO) on March 6, 2008 in Amman, Jordan under the 'Free Zone' system to set up a Phosphoric Acid Plant of 1500 tonnes per day P2O5 capacity at Eshidiya in Jordan. In this company, IFFCO and its affiliates hold 52 % equity, while JPMC holds 48 % equity. |
||||||
| Ransomware | Harman Fitness id27872 View details | United States | Services | — | ||
|
Harman Fitness is a multi-unit franchise operator and management company that owns and runs dozens of Crunch Fitness clubs across the U.S. — operating Crunch locations under franchise agreements with over 40 gyms nationwide |
||||||
| Ransomware | Nippon Medical School Musashi Kosugi Hospital id27871 View details | Japan | Healthcare / Pharma | leaked | ||
|
Nippon Medical School Musashi Kosugi Hospital is a 372-bed regional teaching hospital in Nakahara-ku, Kawasaki (Musashi-Kosugi area), affiliated with Nippon Medical School. Established in 1937, it offers comprehensive services across 36 clinical departments, including emergency and critical care, ICU, NICU, perinatal and pediatric care, cancer treatment, and minimally invasive endovascular procedures. The hospital serves as a regional hub with disaster-resistant facilities and an on-site heliport, and emphasizes advanced, patient-centered care and medical education. |
||||||
| Ransomware | Shiraume Hospital id27870 View details | Japan | Healthcare / Pharma | — | ||
|
Shiramume Hospital is a regional general hospital in Japan providing comprehensive inpatient and outpatient care. It offers services in internal medicine, surgery, emergency care, obstetrics/gynecology, and rehabilitation, supported by diagnostic imaging and laboratory facilities. |
||||||
| Ransomware | GEG Telecomunicazioni id27869 View details | Italy | Manufacturing / Engineering | pending | ||
|
GEG srl (est. 1981) designs and builds integrated mobile radio systems across Italy. Over 35 years it served 500+ public administrations and manages 100,000+ radios. Since 2004 it is Italy’s exclusive DAMM TETRA distributor. It held ~60% of the civilian TETRA market (350+ base stations) |
||||||
| Ransomware | Seoyon E-Hwa Summit id27868 View details | India | Manufacturing / Engineering | — | ||
|
Seoyon E‑Hwa Summit is a subsidiary of Seoyon E‑Hwa that manufactures automotive components, operating as part of Seoyon E‑Hwa’s international production network. |
||||||