Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareExploits 1 CVE

NightSpire

NightSpire is an emerging ransomware operation first observed in early 2025, with reporting indicating discovery around February 2025 and operation of a leak site from March 12, 2025. It evolved from exfiltration-only extortion into a double-extortion model, stealing data and then encrypting victim systems while threatening publication of stolen information on a Tor-based leak site if payment is not made. Multiple sources describe it as a closed-group operation rather than a public RaaS platform, although some reporting has characterized it as operating under a RaaS model, so its exact operating structure is not fully settled.

Observed tradecraft shows broad, opportunistic targeting across countries and sectors. Reported victims span at least 33 countries, with the United States most affected, and sectors including healthcare, education, government, financial services, manufacturing, hospitality, IT services, logistics, and industrial organizations. Mentioned victim organizations or claims include hospitals, schools, government offices, financial institutions, Hyatt Place Chelsea New York, Pioneer Ocean Freight, and Nippon Ceramic.

Documented intrusion activity indicates initial access commonly via Remote Desktop Protocol (RDP). For persistence and remote access, operators used legitimate administration tools including Chrome Remote Desktop and AnyDesk rather than custom backdoors. In observed incidents, Chrome Remote Desktop ran as the Windows service "Chrome Remote Desktop Service," and the email prince1990905@gmail[.]com was associated with a Chrome Remote Desktop deployment. Operators used Everything (voidtools) for file discovery, 7-Zip to create password-protected archives, and MEGAsync/MEGA for likely exfiltration. Huntress also observed use of VMware Workstation and WPS Office in a March 2026 intrusion. Reporting notes that some public descriptions referenced LOLBins such as WMI or PsExec, but in the March 2026 Huntress case the actor instead downloaded external tools.

The encryptor has been reported as Go-based. It traverses accessible drives and paths, appends the .nspire extension to encrypted files, and drops ransom notes in affected folders. NightSpire also has reported capability to encrypt OneDrive files without changing their extensions. Observed ransom note filenames include _nightspire_readme.txt and [nspire_msg].txt. In one March 2026 case, the ransom note claimed theft of 2.5 TB of data, though that volume was not independently validated.

High-confidence indicators from reporting include SHA256 bde50a42efc079edde1a314243ad339db2d42e343fbbcd39117803b0f5960355 for an enc.exe sample dated 2025-12-02 and SHA256 ad67031e2ca68764fe1a7d6632c02b02a299d59efb920710011a9a2ccf4399b7 for an enc.exe sample dated 2026-03-25. Additional observed artifacts include the ransom note names _nightspire_readme.txt and [nspire_msg].txt, the .nspire encrypted-file extension, the Chrome Remote Desktop-associated email prince1990905@gmail[.]com, and the staging path C:\Users[REDACTED]\Downloads.

The content also notes that NightSpire communications have used ProtonMail, OnionMail, and Telegram. Reporting further places NightSpire among the active ransomware groups of 2025-2026, with rapid growth in victim volume and repeated inclusion in ransomware ecosystem tracking.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2024-55591Authentication Bypass in FortiOS and FortiProxy Node.js WebSocket Module

Nightspire, a closed-group operation with OneDrive cloud encryption capability, expanded by 183% from 29 victims to 82, sustaining growth across two consecutive quarters.

via checkpoint research blogresearch.checkpoint.com
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1133External Remote ServicesEvidence1

On a second endpoint within the infrastructure, as illustrated in Figure 2, foothold signals for Chrome Remoting Desktop and AnyDesk were generated shortly after the Huntress agent was installed.

Execution

2 techniques
T1047Windows Management InstrumentationEvidence1

Publicly available reporting of NightSpire ransomware indicates that attacks have included the use of native utilities, or “LOLBins,” like WMI or PsExec.

T1569.002Service ExecutionEvidence1

Publicly available reporting of NightSpire ransomware indicates that attacks have included the use of native utilities, or “LOLBins,” like WMI or PsExec.

Persistence

1 technique
T1133External Remote ServicesEvidence1

On a second endpoint within the infrastructure, as illustrated in Figure 2, foothold signals for Chrome Remoting Desktop and AnyDesk were generated shortly after the Huntress agent was installed.

Discovery

1 technique
T1083File and Directory DiscoveryEvidence1

The threat actor had installed ... Everything, a file search tool ... and then running Everything, from which the threat actor could then be seen, based on process lineage, accessing files via the Everything interface.

Lateral Movement

1 technique
T1021.001Remote Desktop ProtocolEvidence1

This investigation revealed that the threat actor had accessed one endpoint via RDP several days prior to the Huntress agent being installed.

Collection

3 techniques
T1005Data from Local SystemEvidence1

Attackers first steal sensitive files from the victim’s environment, then encrypt everything in sight.

T1074Data StagedEvidence1

The threat actor could then be seen running 7Zip to archive files from a specific folder.

T1560Archive Collected DataEvidence1

The threat actor could then be seen running 7Zip to archive files from a specific folder.

Exfiltration

1 technique
T1567.002Exfiltration to Cloud StorageEvidence1

Two days later, the threat actor could be seen running MEGASync, likely for data exfiltration.

Impact

1 technique
T1486Data Encrypted for ImpactEvidence1

NightSpire operates through a double extortion model. Attackers first steal sensitive files from the victim’s environment, then encrypt everything in sight.

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app3 months ago
hash.sha256●●●●●●●●●●●●View more in app3 months ago
ACTIVITY FEED

Recent activity

15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
May 26, 2026
NightSpire Ransomware Uses RDP Access and Remote Admin Tools for Stealthy Persistence

A Go-based ransomware family that uses double extortion: attackers steal sensitive files, exfiltrate them, then encrypt victim systems and threaten to publish stolen data on a Tor-based leak site if payment is not made. It appends the .nspire extension to encrypted files, drops ransom notes, and has been observed encrypting OneDrive files without changing their extensions.

Read more
checkpoint research blogNews
May 11, 2026
The State of Ransomware - Q1 2026 - Check Point Research

A closed-group ransomware operation with OneDrive cloud encryption capability and exploitation tied to FortiGate access.

Read more
huntress blogNews
Apr 7, 2026
Decoding NightSpire: Ransomware IOCs Aren't Set in Stone | Huntress

A ransomware family first reported in February 2025. The content discusses uncertainty over whether it operates as RaaS or as a closed in-house operation. Observed activity included RDP access, persistence via Chrome Remote Desktop and AnyDesk, use of Everything and 7Zip for staging, MEGASync for exfiltration, and deployment of a file encryptor that used extensions such as .nspire and ransom notes including _nightspire_readme.txt and [nspire_msg].txt.

Read more
scworldNews
Jan 20, 2026
NightSpire ransomware gang alleges Hyatt breach, leaks data | SC Media

Ransomware operation claiming to have breached Hyatt and offering a free download of 48.5 GB of allegedly stolen data (data-theft/extortion behavior).

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.