NetRunner is a financially motivated cybercriminal threat actor associated with ransomware, data exfiltration, and extortion operations. Its documented targeting includes organizations in Japan, the United States, and Malaysia, spanning healthcare, marine construction and transportation services, and retail. During 2026, its healthcare activity included targeting providers and healthcare-related service organizations, with an emphasis on stealing sensitive information for extortion. NetRunner demanded $100 million from Nippon Medical School Musashi Kosugi Hospital in Japan in an incident affecting 131,700 people; the ransom was not paid. Other attributed victims include Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates, Precon Marine Inc, and Main Place Mall. Its country of origin, organizational structure, initial-access methods, and specific malware tooling are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The report attributes a ransomware attack against Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates (MAGOPSA), a US healthcare organization, to netrunner. The breach was reportedly discovered on October 8, 2026, at 22:40 UTC. No technical details or specific ransomware family are provided.
The netrunner ransomware operation lists Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates (MAGOPSA), a US gynecologic oncology practice, as a victim discovered on October 8, 2026. The post provides no stolen-data details, proof of compromise, ransom demand, or deadline.
The post lists an unidentified, masked US organization as a ransomware victim associated with netrunner, with a discovery date of October 5, 2026. It provides no specific breach details, stolen-data claims, supporting evidence, ransom amount, or deadline.
Reportedly conducted a ransomware attack against Precon Marine Inc, a US-based marine contractor specializing in heavy marine construction and subsea services. The content lists both the breach and discovery time as October 3, 2026, at 14:04 UTC, and classifies the victim's business sector as Transportation. No technical evidence or attribution details are provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.