Discovery Enum
- Everything.exe
NightSpire is an emerging ransomware operation first observed in early 2025 that conducts extortion against organizations across multiple countries and sectors, including healthcare, education, government, finance, manufacturing, hospitality, IT services, logistics, and industrial environments.
Profile source: Mallory opens in a new tabNightSpire
NightSpire is an emerging ransomware operation first observed in early 2025 that conducts extortion against organizations across multiple countries and sectors, including healthcare, education, government, finance, manufacturing, hospitality, IT services, logistics, and industrial environments. The group is associated with double extortion, stealing data before encrypting systems and threatening public disclosure to pressure victims. Reporting also indicates the operation may have evolved from earlier exfiltration-only extortion into full ransomware deployment later in 2025.
The malware used by NightSpire is a Go-based Windows encryptor that traverses accessible drives and encrypts files, commonly appending a distinctive extension and dropping ransom notes in affected directories. Observed behavior indicates it can also encrypt OneDrive-hosted files without changing their extensions. In intrusions attributed to NightSpire, operators have relied heavily on legitimate remote administration and utility software rather than bespoke implants, using remote desktop access for footholds and persistence, file-search tools for identifying valuable data, archiving tools for staging theft, and cloud synchronization software for exfiltration.
Initial access has been repeatedly associated with exposed or compromised Remote Desktop Protocol access, and the group has also been linked to exploitation of Fortinet vulnerabilities, including CVE-2024-55591, for privileged access to edge infrastructure. Post-compromise activity has included deployment of legitimate remote management tools for persistence, data discovery across local drives, compression of targeted files into protected archives, likely exfiltration to cloud storage, and subsequent encryption. Public reporting notes variation in tooling, ransom-note formats, and encryptor samples across incidents, which may reflect rapid malware iteration or differences in operator tradecraft.
NightSpire has been described in some reporting as a closed-group operation rather than a public RaaS platform, although other reporting has suggested possible affiliate-style characteristics. At high confidence, it is best characterized as a ransomware threat and extortion operation with broad, opportunistic targeting and a preference for abusing valid remote access and trusted administrative tools to blend into victim environments.
https://t.me/night_spire_team@nightspireteam202535cefe4bc4a98ad73dda4444c700aac9f749efde8f9de6a643a57a5b605bd4e78D663FD10BF662930F4C076CBF95FACFCC4ABD8F1A5E328DE75D0B0237A74E1AE1E0C5C37E7Fnight.spire.team@gmail.comnight.spire.team@onionmail.orgnight.spire.team@proton.menightspireteam.receiver@onionmail.orgReported operators
Malware Signature: Trojan-Ransom."Nightspire" ... Ransomware/Win."Nightspire".C5769860 Ransomware/Win."Nightspire".C5775165
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.