Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

nightspire Ransomware Group

Ransomware group profile

186Victims
South KoreaSource country
79Impact score

Description

NightSpire is a financially motivated ransomware group that emerged in early 2025, targeting small to medium-sized enterprises across various sectors. The group employs a double extortion strategy, encrypting data after exfiltration, and has operated a Dark Web leak site to threaten the public release of stolen data since March 2025.

Key insights

  • Utilizes a double extortion model by encrypting stolen data and threatening public release.
  • Gains initial access using exploits like CVE-2024-55591, RDP brute-forcing, and phishing.
  • Features a custom ransomware payload written in Go that appends the '.nspire' extension to encrypted files.
  • Employs living-off-the-land techniques, leveraging legitimate tools for data exfiltration.
  • Targets a wide range of industries with ransom demands ranging from $150,000 to $2 million.
  • Rapidly advanced from operational immaturity to a robust operation with Ransomware-as-a-Service offerings.

Threat Level & Status Breakdown

For nightspire · Based on incidents in selected period

No victim data for this group in the selected period.

First seenSep 2025
Last seenAug 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 28, 2026

Recent activity

Monthly attack count for nightspire in the selected period

186Total attacks
35peak in Feb
15.5avg / month
SepOctNovDecJanFebMarAprMayJunJulAug09182736

Intelligence

IOCs, YARA/Sigma rules, and related families for nightspire

  1. c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
  2. 7eec7d07587112777016e5742c0d002d7e64a3e1fe7bde82fed8f65e3663456a
  3. 35cefe4bc4a98ad73dda4444c700aac9f749efde8f9de6a643a57a5b605bd4e7
  4. e1c371c7c39c16d208bcbaa5b5d0714df696e6ef68b95a880673a904527c8b96
  5. 7ffb8a403a298e5b0d5f8bf3c6d119e6
  6. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
  7. e275b8a02bf23b565bdaabadb220b39409eddc6b8253eb04e0f092d697e3b53d
  8. 0170601e27117e9639851a969240b959
  9. 7a4aee1910b84c6715c465277229740dfc73fa39
  10. 32e10dc9fe935d7c835530be214142041b6aa25ee32c62648dea124401137ea5
  11. 989daab910436b48f422fe60daa17a95a486e87d
  12. 2bf543faf679a374af5fc4848eea5a98
  13. e2d7d65a347b3638f81939192294eb13
  14. 072147d034e6db2db9f81bc9b74e0e59b79a1ee6
  15. 82afcebc49f49b758de83b3275c91137
  16. 96bc46719eb773b1f13b63606898d1837cbd4169
  17. d5f9595abb54947a6b0f8a55428ca95e6402d2aeb72cbc109beca457555a99a6
  18. e06520c65bf27d9110d68ecc0de0e0824c3a99be080ead1a5b5be8fd2a26d12d
  19. 94dd3315fca4c31ef61b7865c3b8983f
  20. f5da096e2ae6079c4670ddd6566244618056a22e
  21. c5f526cc62688cf34c49d098dab81e24e4294f832ada57433ef505d5ac6da8f3
  22. eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577
  23. bde50a42efc079edde1a314243ad339db2d42e343fbbcd39117803b0f5960355
  24. ad67031e2ca68764fe1a7d6632c02b02a299d59efb920710011a9a2ccf4399b7
  25. 69f5515ff3f554233840ad2f2397b345f955013017a9ae14ed4e762f52d936af
View full IOC feed54 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for nightspire

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1046

T1046

T1021

T1021

T1562

T1562

T1059

T1059

T1105

T1105

T1005

T1005

T1071

T1071

T1027

T1027

T1080

T1080