NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan, notably demanding a $100M ransom from Nippon Medical School Musashi Kosugi Hospital. Known victims: 6 1 ransom note(s) on file
Objectives
Executive Summary
NetRunner is a medium-sophistication criminal ransomware group active since 2025, targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan. Known for demanding significant ransoms, such as $100M from Nippon Medical School Musashi Kosugi Hospital, NetRunner operates with a primary motivation of financial gain through ransomware campaigns.
Goals & Targeting
NetRunner's strategic objectives are centered around financial gain through ransomware activity. The group appears to target sectors with deep pockets or critical operations that would be willing to pay significant ransoms, such as healthcare (e.g., hospitals) and telecommunications. The targeting of multiple countries suggests an operational capacity that may leverage language-specific capabilities or regional expertise. Victims have included both private companies and public entities, indicating a broad aperture in terms of victimology.
Enhanced Description
NetRunner is a mid-tier criminal threat actor specializing in ransomware attacks. The group has demonstrated the ability to target multiple critical sectors, including healthcare and telecommunications, across geographically diverse regions such as Japan, Italy, the United States, and Jordan. NetRunner's operations are characterized by significant financial demands, with one notable instance involving a $100M ransom demand from Nippon Medical School Musashi Kosugi Hospital. The group has been active since at least 2025 but was first formally observed on April 3, 2026. NetRunner's campaigns appear to be financially motivated, focusing on maximizing monetary gains through the deployment of sophisticated ransomware infrastructure. Campaigns have varied in both targets and methodologies, reflecting a modular approach that allows for rapid adaptation to defensive measures.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
NetRunner has conducted multiple campaigns targeting a variety of industries and geographies. Notable operations include attacks on healthcare providers such as Shiraume Hospital, telecommunications companies like GEG Telecomunicazioni, and manufacturing sectors like Harman Fitness. The group appears to favor high-value targets within critical infrastructure and private sector entities. Campaign patterns suggest a focus on maximizing financial gain rather than disrupting operations for other purposes.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in NetRunner's ransomware activity due to multiple confirmed campaigns and known victims. However, the lack of detailed information on specific tools or techniques leaves some gaps in understanding their full capabilities.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
6
Campaigns
0
IOCs
0
Observed Data
0
Tactics