Discovery Enum
- Everything.exe
NightSpire is an emerging ransomware family and associated extortion operation first observed in early 2025.
Profile source: Mallory opens in a new tabNightSpire
NightSpire is an emerging ransomware family and associated extortion operation first observed in early 2025. It evolved from exfiltration-focused extortion into a double-extortion model in which operators steal data and then encrypt victim systems while threatening public disclosure of stolen information. The malware has been described as a Go-based encryptor that traverses accessible drives, appends a distinctive encrypted-file extension in some observed cases, drops ransom notes, and can also encrypt OneDrive-hosted files without changing their extensions.
Observed intrusions indicate that NightSpire commonly gains initial access through exposed or compromised Remote Desktop Protocol access, and reporting also links the group to exploitation of Fortinet edge-device vulnerabilities such as CVE-2024-55591 for initial access in some campaigns. Rather than relying primarily on bespoke backdoors, operators have repeatedly used legitimate remote administration tools to maintain access and persistence, including Chrome Remote Desktop and AnyDesk. Post-compromise activity has included file discovery with common administrative utilities, compression of targeted data into archives, and exfiltration to cloud storage services before encryption. Multiple investigations also note variation in tooling, ransom-note formats, and encryptor samples across incidents, suggesting ongoing malware development or possible affiliate-driven operational differences.
NightSpire has targeted a broad range of sectors, including healthcare, education, government, finance, manufacturing, hospitality, logistics, and IT services, with victims reported across dozens of countries and a notable concentration in the United States. Industrial reporting also places the group among ransomware actors affecting manufacturing and other industrial organizations. Public reporting variously characterizes NightSpire as a closed-group operation and, in some accounts, as operating in a RaaS-like manner; the group’s exact operating model is therefore not fully settled. High-confidence reporting supports that it is an active ransomware threat using data theft, encryption, and public-leak pressure to extort organizations.
https://t.me/night_spire_team@nightspireteam202535cefe4bc4a98ad73dda4444c700aac9f749efde8f9de6a643a57a5b605bd4e78D663FD10BF662930F4C076CBF95FACFCC4ABD8F1A5E328DE75D0B0237A74E1AE1E0C5C37E7Fnight.spire.team@gmail.comnight.spire.team@onionmail.orgnight.spire.team@proton.menightspireteam.receiver@onionmail.orgReported operators
Malware Signature: Trojan-Ransom."Nightspire" ... Ransomware/Win."Nightspire".C5769860 Ransomware/Win."Nightspire".C5775165
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.