Ransomware needs a way in. Stolen credentials are the cheapest one.
nightspire Ransomware Group
Ransomware group profile
Description
NightSpire is a financially motivated ransomware group that emerged in early 2025, targeting small to medium-sized enterprises across various sectors. The group employs a double extortion strategy, encrypting data after exfiltration, and has operated a Dark Web leak site to threaten the public release of stolen data since March 2025.
Key insights
- •Utilizes a double extortion model by encrypting stolen data and threatening public release.
- •Gains initial access using exploits like CVE-2024-55591, RDP brute-forcing, and phishing.
- •Features a custom ransomware payload written in Go that appends the '.nspire' extension to encrypted files.
- •Employs living-off-the-land techniques, leveraging legitimate tools for data exfiltration.
- •Targets a wide range of industries with ransom demands ranging from $150,000 to $2 million.
- •Rapidly advanced from operational immaturity to a robust operation with Ransomware-as-a-Service offerings.
Threat Level & Status Breakdown
For nightspire · Based on incidents in selected period
No victim data for this group in the selected period.
Recent activity
Monthly attack count for nightspire in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for nightspire
- c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
- 7eec7d07587112777016e5742c0d002d7e64a3e1fe7bde82fed8f65e3663456a
- 35cefe4bc4a98ad73dda4444c700aac9f749efde8f9de6a643a57a5b605bd4e7
- e1c371c7c39c16d208bcbaa5b5d0714df696e6ef68b95a880673a904527c8b96
- 7ffb8a403a298e5b0d5f8bf3c6d119e6
- 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
- e275b8a02bf23b565bdaabadb220b39409eddc6b8253eb04e0f092d697e3b53d
- 0170601e27117e9639851a969240b959
- 7a4aee1910b84c6715c465277229740dfc73fa39
- 32e10dc9fe935d7c835530be214142041b6aa25ee32c62648dea124401137ea5
- 989daab910436b48f422fe60daa17a95a486e87d
- 2bf543faf679a374af5fc4848eea5a98
- e2d7d65a347b3638f81939192294eb13
- 072147d034e6db2db9f81bc9b74e0e59b79a1ee6
- 82afcebc49f49b758de83b3275c91137
- 96bc46719eb773b1f13b63606898d1837cbd4169
- d5f9595abb54947a6b0f8a55428ca95e6402d2aeb72cbc109beca457555a99a6
- e06520c65bf27d9110d68ecc0de0e0824c3a99be080ead1a5b5be8fd2a26d12d
- 94dd3315fca4c31ef61b7865c3b8983f
- f5da096e2ae6079c4670ddd6566244618056a22e
- c5f526cc62688cf34c49d098dab81e24e4294f832ada57433ef505d5ac6da8f3
- eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577
- bde50a42efc079edde1a314243ad339db2d42e343fbbcd39117803b0f5960355
- ad67031e2ca68764fe1a7d6632c02b02a299d59efb920710011a9a2ccf4399b7
- 69f5515ff3f554233840ad2f2397b345f955013017a9ae14ed4e762f52d936af
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for nightspire
T1486
T1486
T1490
T1490
T1078
T1078
T1046
T1046
T1021
T1021
T1562
T1562
T1059
T1059
T1105
T1105
T1005
T1005
T1071
T1071
T1027
T1027
T1080
T1080
Affected countries(69)
Countries where this group has been reported to target or leak victims.