NightSpire is a ransomware family associated with a financially motivated extortion operation first observed in early 2025. The operation evolved from data-theft extortion into double extortion, stealing sensitive information before encrypting victim systems and threatening publication on a Tor-based leak site. Its targeting is broad and international, encompassing healthcare, education, government, financial services, manufacturing, hospitality, IT services, and logistics.
The Go-based encryptor traverses accessible drives and directories, encrypts files, and places ransom notes in affected folders. NightSpire also supports encryption of OneDrive files without changing their extensions. Windows deployments have been observed, with changes to encryptor binaries and ransom-note contents across incidents.
Associated intrusions have used Remote Desktop Protocol access and exploitation of CVE-2024-55591, an authentication-bypass vulnerability affecting FortiOS and FortiProxy. Operators establish persistent access through legitimate remote-administration tools, including Chrome Remote Desktop and AnyDesk. They use Everything to locate valuable files, 7-Zip to prepare password-protected archives, and MEGAsync to transfer stolen data to cloud storage before ransomware deployment. Tooling and intrusion techniques vary between incidents.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One clear example is CVE-2024-55591 in FortiOS; that flaw lets remote actors bypass authentication and walk straight into protected networks. NightSpire leaned on this vulnerability during its early 2025 campaigns.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NightSpire runs double extortion: steals data first, encrypts second, then threatens public leak via a dark web site with countdown timers.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation whose industrial victim claims declined sharply in Q2 2026.
A Go-based ransomware family that uses double extortion: attackers steal sensitive files, exfiltrate them, then encrypt victim systems and threaten to publish stolen data on a Tor-based leak site if payment is not made. It appends the .nspire extension to encrypted files, drops ransom notes, and has been observed encrypting OneDrive files without changing their extensions.
A closed-group ransomware operation with OneDrive cloud encryption capability and exploitation tied to FortiGate access.
A ransomware family first reported in February 2025. The content discusses uncertainty over whether it operates as RaaS or as a closed in-house operation. Observed activity included RDP access, persistence via Chrome Remote Desktop and AnyDesk, use of Everything and 7Zip for staging, MEGASync for exfiltration, and deployment of a file encryptor that used extensions such as .nspire and ransom notes including _nightspire_readme.txt and [nspire_msg].txt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.