NightSky is a file-encrypting ransomware family associated with China-based ransomware operator DEV-0401. Beginning as early as January 4, 2022, the operator exploited CVE-2021-44228 in internet-facing VMware Horizon systems, with successful intrusions leading to NightSky deployment. NightSky has also appeared in operations involving HUI Loader.
Analyzed Windows samples use VMProtect to hinder reverse engineering and implement multithreaded file encryption with statically linked Mbed TLS cryptographic routines. NightSky generates a victim-specific RSA-2048 key pair and encrypts the victim's private key using an embedded attacker RSA-2048 public key. It generates a unique 16-byte AES key for each file, encrypts file data using AES-128-CBC with a hardcoded initialization vector, and encrypts the per-file AES key with the victim's RSA public key. The encrypted per-file key is stored in the encrypted file's footer. Encryption is capped at 1.5 MiB per file.
NightSky shares extensive code, threading and synchronization logic, key-management routines, and encrypted-file structure with Rook ransomware. A notable distinction is NightSky's use of AES-CBC rather than Rook's intermittent AES-ECB encryption. These technical similarities establish a close code relationship but do not independently establish common authorship.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During routine sandbox hunting analysis, the Uptycs Threat Research team uncovered evidence of an ongoing live campaign exploiting the Log4j vulnerability, which commenced in January 2024.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Successful intrusions in these campaigns led to the deployment of the NightSky ransomware.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NightSky is a ransomware family referenced as part of BRONZE STARLIGHT-linked operations that also used HUI Loader variants.
Named in the historical list of malware deployed through Log4j exploitation. The reference places it among Linux payloads but provides no supporting technical analysis.
Ransomware group mentioned alongside Cheers as reportedly backed by a China-based cybercrime group.
周辺グループとの関係性から、特定国家への帰属可能性を示唆する事例として挙げられているランサムウェア。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.