Skip to content

NightSpire

NightSpire is an emerging ransomware family and associated extortion operation first observed in early 2025.

Profile source: Mallory opens in a new tab

NightSpire

Family profile

NightSpire is an emerging ransomware family and associated extortion operation first observed in early 2025. It evolved from exfiltration-focused extortion into a double-extortion model in which operators steal data and then encrypt victim systems while threatening public disclosure of stolen information. The malware has been described as a Go-based encryptor that traverses accessible drives, appends a distinctive encrypted-file extension in some observed cases, drops ransom notes, and can also encrypt OneDrive-hosted files without changing their extensions.

Observed intrusions indicate that NightSpire commonly gains initial access through exposed or compromised Remote Desktop Protocol access, and reporting also links the group to exploitation of Fortinet edge-device vulnerabilities such as CVE-2024-55591 for initial access in some campaigns. Rather than relying primarily on bespoke backdoors, operators have repeatedly used legitimate remote administration tools to maintain access and persistence, including Chrome Remote Desktop and AnyDesk. Post-compromise activity has included file discovery with common administrative utilities, compression of targeted data into archives, and exfiltration to cloud storage services before encryption. Multiple investigations also note variation in tooling, ransom-note formats, and encryptor samples across incidents, suggesting ongoing malware development or possible affiliate-driven operational differences.

NightSpire has targeted a broad range of sectors, including healthcare, education, government, finance, manufacturing, hospitality, logistics, and IT services, with victims reported across dozens of countries and a notable concentration in the United States. Industrial reporting also places the group among ransomware actors affecting manufacturing and other industrial organizations. Public reporting variously characterizes NightSpire as a closed-group operation and, in some accounts, as operating in a RaaS-like manner; the group’s exact operating model is therefore not fully settled. High-confidence reporting supports that it is an active ransomware threat using data theft, encryption, and public-leak pressure to extort organizations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Persistence

Operational record

9
Indicators
1
YARA rules
4
Ransom notes
11
Negotiations
6
Leak sites
1 available

Discovery Enum

  • Everything.exe

Exfiltration

  • MEGA
  • WinSCP

Published indicators

Telegram

2 total
  • https://t.me/night_spire_team
  • @nightspireteam2025

Sha256

2 total
  • 35cefe4bc4a98ad73dda4444c700aac9
  • f749efde8f9de6a643a57a5b605bd4e7

Tox

1 total
  • 8D663FD10BF662930F4C076CBF95FACFCC4ABD8F1A5E328DE75D0B0237A74E1AE1E0C5C37E7F

Email

4 total
  • night.spire.team@gmail.com
  • night.spire.team@onionmail.org
  • night.spire.team@proton.me
  • nightspireteam.receiver@onionmail.org

Recent claims

Reported operators

Threat actors

1 named in public reporting
NightSpire

Malware Signature: Trojan-Ransom."Nightspire" ... Ransomware/Win."Nightspire".C5769860 Ransomware/Win."Nightspire".C5775165

Exploited software

Vulnerabilities linked to NightSpire

1 CVEs

MITRE ATT&CK

NightSpire in ATT&CK

41 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.