NightSpire is an emerging financially motivated ransomware and extortion group active since early 2025. It is assessed as a relatively low-sophistication operation and is likely a rebrand or continuation of the Rbfs ransomware group, based on overlapping victims, shared operator personas, and the disappearance of Rbfs activity as NightSpire emerged. Known associated personas include xdragon128 and cuteliyuan. NightSpire conducts opportunistic attacks across sectors, with observed victimization including manufacturing, healthcare, financial services, energy, education, professional services, business services, consumer services, and real estate-related organizations. Reporting indicates a concentration on small and medium-sized organizations, while broader leak-site tracking also places the group among actors targeting healthcare entities in the EMEA region. The group initially emphasized data theft and extortion and later adopted double extortion, combining data exfiltration with encryption and threats of public disclosure. NightSpire has operated a leak site used to name and shame non-paying victims, publish stolen data, and threaten sale of exfiltrated information. Aggressive pressure tactics have included short payment deadlines and direct contact with employees during negotiations. Observed tradecraft includes exploitation of vulnerable internet-facing perimeter systems for initial access, including Fortinet devices via CVE-2024-55591, followed by lateral movement and data theft. NightSpire has used legitimate tools and LOLBins for defense evasion and operational activity, including common file-transfer and archiving utilities, as well as network scanning and FTP-capable tooling. Public reporting also links the group to use of legitimate exfiltration utilities and to post-compromise activity consistent with opportunistic enterprise ransomware intrusions. NightSpire has been tracked in ransomware claim reporting through 2026, including periods of moderate activity and subsequent decline in weekly rankings. The actor is best characterized as a criminal ransomware/extortion operation rather than a state-directed espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as prior-week comparison background and not part of the current week's active ranking.
Mentioned only as a declining group in quarterly rankings.
Ransomware group listed among the more active groups of the week with 12 claimed attacks.
Named as the threat group responsible for a ransomware attack and data breach against Kates Nussman Ellis Earle & Landolfi LLP.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.