Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors netrunner

Description

NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan, notably demanding a $100M ransom from Nippon Medical School Musashi Kosugi Hospital. Known victims: 6 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

NetRunner is a medium-sophistication criminal ransomware group active since 2025, targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan. Known for demanding significant ransoms, such as $100M from Nippon Medical School Musashi Kosugi Hospital, NetRunner operates with a primary motivation of financial gain through ransomware campaigns.

Goals & Targeting

NetRunner's strategic objectives are centered around financial gain through ransomware activity. The group appears to target sectors with deep pockets or critical operations that would be willing to pay significant ransoms, such as healthcare (e.g., hospitals) and telecommunications. The targeting of multiple countries suggests an operational capacity that may leverage language-specific capabilities or regional expertise. Victims have included both private companies and public entities, indicating a broad aperture in terms of victimology.

Enhanced Description

NetRunner is a mid-tier criminal threat actor specializing in ransomware attacks. The group has demonstrated the ability to target multiple critical sectors, including healthcare and telecommunications, across geographically diverse regions such as Japan, Italy, the United States, and Jordan. NetRunner's operations are characterized by significant financial demands, with one notable instance involving a $100M ransom demand from Nippon Medical School Musashi Kosugi Hospital. The group has been active since at least 2025 but was first formally observed on April 3, 2026. NetRunner's campaigns appear to be financially motivated, focusing on maximizing monetary gains through the deployment of sophisticated ransomware infrastructure. Campaigns have varied in both targets and methodologies, reflecting a modular approach that allows for rapid adaptation to defensive measures.

Key Capabilities

  • Ransomware deployment
  • Targeted attacks on critical sectors
  • Multi-regional operational reach
  • High-value ransom demands

MITRE ATT&CK Tactics

Data Exfiltration
Impact

ATT&CK Techniques

T1078.001
T1547
T1003
T1059.001

Software / Tooling

NetRunner Ransomware
Cobalt Strike

Campaigns & Victims

NetRunner has conducted multiple campaigns targeting a variety of industries and geographies. Notable operations include attacks on healthcare providers such as Shiraume Hospital, telecommunications companies like GEG Telecomunicazioni, and manufacturing sectors like Harman Fitness. The group appears to favor high-value targets within critical infrastructure and private sector entities. Campaign patterns suggest a focus on maximizing financial gain rather than disrupting operations for other purposes.

IOC Patterns

  • Ransomware encryption patterns
  • Use of Remote Desktop Protocol (RDP) for initial access
  • Encrypted files with .netrunner extension

Recommended Actions

  • Implement multi-factor authentication for RDP access
  • Monitor for suspicious network activity indicative of ransomware campaigns
  • Regularly back up critical systems and store backups offline
  • Conduct user training to detect phishing attempts associated with NetRunner's TTPs

Suggested Tags

ransomware
financial-gain
healthcare-targeting
telecommunications-targeting

Confidence Assessment

High confidence in NetRunner's ransomware activity due to multiple confirmed campaigns and known victims. However, the lack of detailed information on specific tools or techniques leaves some gaps in understanding their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

6

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
ransomware
financial-gain
healthcare-targeting
telecommunications-targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 3, 2026
Last Seen
Apr 3, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.