Quick Summary
AllegedExecutive Summary
m3rx ransomware has claimed Noon Sugar Mills Limited, an industrial manufacturing firm based in the United Arab Emirates, listing the company on September 29, 2026. This claim was identified through SOCRadar’s Dark Web Monitoring services. The listing of Noon Sugar Mills Limited was one of several claims published concurrently by m3rx, indicating a broad campaign targeting organizations across diverse geographic locations. The industrial manufacturing sector, especially in regions with significant infrastructure development, can be attractive targets due to the potential for operational disruption and high impact. The m3rx group has been active in claiming victims, with seven prior victims identified within the last 60 days prior to this listing. Their typical targets span across Professional Services, Technology, and Retail & E-Commerce sectors, predominantly in the United States, Brazil, and Canada. The inclusion of Noon Sugar Mills Limited marks a notable expansion of m3rx’s operational geography, as it represents their first publicly claimed victim in the Middle East within this monitoring period, extending their reach beyond their usual North and South American focus.
Technical Analysis
SOCRadar’s investigation into noonsugar[.]com yielded ten records classified as category A (employee credentials on organization-controlled systems), all associated with the subdomain tiger[.]noonsugar.com. Specifically, two records related to the OWA authentication endpoint directly, and eight records pertained to the root subdomain (tiger[.]noonsugar.com). The username patterns observed included common designations such as “administrator” and other employee identifiers. These exposed credentials were found to be fresh, with a data range from March to September 2026, indicating a sustained six-month period of exposure without rotation. These ten records represent direct Outlook Web Access credentials for multiple employees, exposed over a period of six months. OWA credentials are considered high-fidelity indicators for initial access in ransomware operations. Their exposure can grant attackers access to company email and potentially facilitate credential stuffing attacks against other Microsoft services. This sustained exposure period, without credential rotation, significantly increases the risk of exploitation by threat actors like m3rx. The confirmed presence of these OWA credentials suggests a significant security vulnerability for Noon Sugar Mills Limited. The prolonged exposure period of these credentials, from March to September 2026, signifies a lack of timely security practices, such as regular password rotation or multi-factor authentication implementation on critical services. Given that OWA credentials are a primary vector for ransomware, organizations are strongly advised to treat all such exposed records as compromised, immediately rotate affected accounts, restrict external OWA access pending thorough audits, and meticulously review authentication logs for suspicious activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.