Ransomware needs a way in. Stolen credentials are the cheapest one.
netrunner Ransomware Group
Ransomware group profile
6Victims
Description
No description available for this group.
Threat Level & Status Breakdown
For netrunner ยท Based on incidents in selected period
2threat level
Claimed100.0%6
First seenApr 2026
Last seenApr 2026
Avg ransomโ
Payment rateโ
Recent activity
Monthly attack count for netrunner in the selected period
6Total attacks
6peak in Apr
6avg / month
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for netrunner
Defense Evasion
T1562
Impair Defenses
T1036
Masquerading
Execution
T1047
Windows Management Instrumentation
T1059
Command and Scripting Interpreter
Impact
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
Lateral Movement
T1021
Remote Services
T1080
Taint Shared Content
Persistence
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
Victims(6)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Jordan India Fertiliser Company (JIFCO) | Jordan | Claimed | 6 months ago | |
| Crunch Fitness | United States | Claimed | 6 months ago | |
| Nippon Medical School | Japan | Claimed | 6 months ago | |
| Shiraume Hospital | Japan | Claimed | 6 months ago | |
| GEG Telecomunicazioni | Italy | Claimed | 6 months ago | |
| Seoyon EโHwa | India | Claimed | 6 months ago |
Affected countries(5)
Countries where this group has been reported to target or leak victims.