Skip to content

NightSky

NightSky is a Windows ransomware family active by at least 2021–2022 and associated in multiple reporting streams with China-linked cybercriminal activity.

Profile source: Mallory opens in a new tab

NightSky

Family profile

NightSky is a Windows ransomware family active by at least 2021–2022 and associated in multiple reporting streams with China-linked cybercriminal activity. It has been discussed alongside ransomware operations such as Cheers and has also appeared in broader clustering of China-nexus intrusion activity that reused shared tooling, including HUI Loader variants. NightSky has additionally been cited in relationship mapping of ransomware groups where affiliate overlap, rebranding, and operator connections complicate attribution.

Technically, NightSky is assessed with high confidence to be closely derived from Rook ransomware, likely as a fork. Comparative reverse engineering found extensive similarity in cryptographic implementation, threading, synchronization, and file-encryption workflow, beyond what would be expected from incidental overlap. Both families use statically linked Mbed TLS code and implement a hybrid encryption design in which the malware generates a victim RSA-2048 key pair, encrypts the victim private key with an embedded attacker-controlled RSA-2048 public key, and generates a unique 16-byte AES key per file that is then encrypted with the victim public key and stored in the encrypted file footer. NightSky differs from Rook in some implementation details, notably using AES-128-CBC with a hardcoded IV, while preserving a highly similar encrypted-file structure and overall logic. Analysis has also noted that NightSky samples were protected with VMProtect, increasing reverse-engineering difficulty.

NightSky’s known behavior is consistent with enterprise-targeting ransomware used for data theft and extortion. It encrypts files on compromised Windows systems and has been referenced in reporting focused on double-extortion ecosystems and leak-site activity. It has also been observed in operational contexts involving malware loaders used to stage later payloads, indicating use within broader post-compromise intrusion chains rather than as a purely standalone commodity encryptor.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Post Exploitation

Operational record

1
YARA rules
1
Leak sites
0 available

Reported operators

Threat actors

2 named in public reporting
menuPass

一方、NIGHT SKYなどのように、周辺グループとの繋がりから特定国に帰属する攻撃者像が浮き上がってくるケースもある。

Cinnamon Tempest

一方、NIGHT SKYなどのように、周辺グループとの繋がりから特定国に帰属する攻撃者像が浮き上がってくるケースもある。

MITRE ATT&CK

NightSky in ATT&CK

2 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.