Skip to content
CTI Academy Sponsor CTI Academy
Ransomware victim Manufacturing

Netech (Neeser Technik AG)

Listed by Payload on · organisation based in Switzerland

Disclosed
Sep 28, 2026
Leak-site listing date
Threat group
Payload
78 victims listed
Country
Switzerland
#13 most targeted
Sector
Manufacturing

ThreatAI analysis

Compiled from this incident record and the threat intelligence profile for Payload. Figures and technique mappings are quoted from the source data, not inferred.

About Netech (Neeser Technik AG)

Netech (Neeser Technik AG) is a Swiss engineering and industrial services company based in Seuzach. It specializes in comprehensive maintenance, retrofitting, and overhauls of industrial machinery and manufacturing systems. The firm provides end-to-end technical support for production facilities, covering mechanical engineering, pneumatics, and electrical control systems.

Source record: ransomware.live

About the Payload group

Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site. Payload has listed 75 victims since February 2026.

How Payload is documented to operate

Native API T1106 Execution

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference
Obfuscated Files or Information T1027 Stealth

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.

Mitigations: User Training, Behavior Prevention on Endpoint, Antivirus/Antimalware, Audit

MITRE ATT&CK reference
File Deletion T1070.004 Stealth

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint. There are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well. Examples of built-in Command and Scripting Interpreter functions include <codedel</code on Windows, <coderm</code or <codeunlink</code on Linux and macOS, and rm on ESXi.

MITRE ATT&CK reference
Execution Guardrails T1480 Stealth

Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign. Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses. Guardrails can be used to prevent exposure of capabilities in environments that are not intended to be compromised or operated within.

Mitigations: Do Not Mitigate

MITRE ATT&CK reference
Process Discovery T1057 Discovery

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. In Windows environments, adversaries could obtain details on running processes using the Tasklist utility via cmd or <codeGet-Process</code via PowerShell.

MITRE ATT&CK reference
System Information Discovery T1082 Discovery

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes. Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <codesystemsetup</code configuration tool on macOS.

MITRE ATT&CK reference

MITRE ATT&CK techniques attributed to Payload across its recorded activity, not a finding about how Netech (Neeser Technik AG) was reached.

Incident analysis

Netech (Neeser Technik AG) was listed by Payload ransomware, a group with 78 victims recorded in this database. The listing appeared on the group's leak site on September 28, 2026.

Netech (Neeser Technik AG) is based in Switzerland and operates in the Manufacturing sector. Switzerland ranks #13 worldwide for ransomware disclosures, with 217 victims in this database.

Sector context. Manufacturing companies are frequently targeted because production downtime directly translates to financial loss. Ransomware operators exploit this time-sensitivity to demand higher ransoms and faster payment.

Payload typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.

Frequently asked questions

Was Netech (Neeser Technik AG) attacked by ransomware?

Yes. Netech (Neeser Technik AG) was listed as a victim of the Payload ransomware group on September 28, 2026. The organisation is based in Switzerland and operates in the Manufacturing sector. The disclosure appeared on the group's dark web leak site.

Which ransomware group attacked Netech (Neeser Technik AG)?

Netech (Neeser Technik AG) was attacked by Payload ransomware. Payload is one of the most active ransomware groups, having claimed 78 victims globally. The group typically employs a double-extortion model: encrypting the victim's files and threatening to publish stolen data.

When did the Netech (Neeser Technik AG) ransomware attack occur?

The ransomware attack on Netech (Neeser Technik AG) was disclosed on September 28, 2026. This date reflects when the victim was published on the threat group's leak site, which may differ from the actual date of initial compromise.

What data was stolen in the Netech (Neeser Technik AG) ransomware attack?

The specific data stolen from Netech (Neeser Technik AG) has not been independently verified by this platform. Ransomware groups typically exfiltrate data before encrypting systems and use the threat of publication to pressure victims. As a Manufacturing organisation, Netech (Neeser Technik AG) likely held sensitive business data, client information, and operational records.

How can organisations protect against Payload attacks?

To defend against Payload and similar threat actors, organisations should: maintain regular offline backups tested for restoration; implement network segmentation to limit lateral movement; deploy multi-factor authentication on all remote access; use endpoint detection and response (EDR) tools; conduct regular phishing and security awareness training; and monitor threat intelligence feeds for indicators of compromise (IOCs) associated with active groups.