nightspire
Group profile
NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing, healthcare, finance, and education sectors in the US, France, India, Taiwan, and Japan, using aggressive double-extortion with ransom deadlines as short as two days.
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
Compromised RDP credentials used for initial access.
T1110Brute Force
Brute-forcing remote login credentials (RDP) and MFA fatigue attacks.
T1190Exploit Public-Facing Application
Exploitation of CVE-2024-55591 — FortiOS/FortiProxy authentication bypass; unauthenticated attackers gain super-admin privileges via crafted POST requests to /api/v2/cmdb/.
T1566Phishing
Malicious attachments and drive-by downloads.
Execution
Persistence
T1053Scheduled Task/Job
Persistence via Windows Task Scheduler; service creation and modification.
T1136Create Account
Administrative account creation post-exploitation on FortiGate devices.
T1547Boot or Logon Autostart Execution
Reboot persistence mechanisms.
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Persistence via HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and RunOnce.
Privilege Escalation
T1068Exploitation for Privilege Escalation
FortiOS super-admin access via CVE-2024-55591 exploitation.
Defense Evasion
T1027Obfuscated Files or Information
Obfuscation techniques to evade analysis.
T1036Masquerading
Renamed processes and use of legitimate tools (WinSCP, MEGACmd, 7-Zip, PsExec) blending into normal operations.
T1070Indicator Removal
Removal of forensic indicators from compromised systems.
T1218System Binary Proxy Execution
Execution via legitimate system binaries (LOLBins) to evade detection.
Credential Access
Discovery
T1046Network Service Discovery
Network scanning to map internal infrastructure using Advanced IP Scanner.
T1057Process Discovery
Process enumeration on compromised systems.
T1082System Information Discovery
Collection of system details from compromised hosts.
T1083File and Directory Discovery
File indexing and enumeration using Everything.exe.
Lateral Movement
Collection
Exfiltration
T1041Exfiltration Over C2 Channel
Data exfiltration over C2 channel.
T1048Exfiltration Over Alternative Protocol
Data exfiltration via WinSCP (v6.3.7) and Rclone over encrypted channels.
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
MEGACmd used to upload stolen data to MEGA cloud storage. Documented exfiltration of 1.5TB from a single healthcare victim.
Command and Control
Impact
T1486Data Encrypted for Impact
Hybrid AES-256 (file content) + RSA-2048 (key protection) encryption; appends .nspire extension; processes files in 1MB block chunks. Double extortion model — data theft + encryption.
Resource Development
T1587Develop Capabilities
Custom Go-based ransomware development with modular architecture.
Recent victims
showing 50 of 296| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2026-06-19 | Artistic Smilesartisticsmiles.org | Consumer Services | US |
| 2026-06-17 | legendsmn(Blue Ox, Paul Bunyan, Lumberjack Electric)legendsmn.com | Energy | US |
| 2026-05-31 | dean cosmetic dentistrydeancosmeticdentistry.com | Healthcare | US |
| 2026-06-01 | G Guy E******* & F*******, P.A | Financial Services | |
| 2026-06-16 | C Central Texas ***** ***** | Not Found | |
| 2026-06-16 | R Ri***** Co**** Europe S.r.l. | Not Found | |
| 2026-06-05 | B B****S I******t***l | Business Services | |
| 2026-06-02 | Sheraton Miramar Resort El Gounawww.elgouna.com/hotels/sheraton-miramar-resort-el-gouna | Hospitality and Tourism | EG |
| 2026-06-13 | G G**** R****l*e | Not Found | |
| 2026-05-27 | Silsbee Police Departmentwww.silsbeeisd.org/departments/silsbee-isd-police-department | Public Sector | US |
| 2026-05-29 | K****** County. Mi**e**takcmn.us | Public Sector | US |
| 2026-05-17 | WaxWorks Incwww.twaxworks.com | Consumer Services | US |
| 2026-05-27 | Blue Nile Medical Centerbluenilemedical.com | Healthcare | US |
| 2026-05-22 | P Pattono S.r.l | Business Services | IT |
| 2026-05-24 | S Sierra West Jewelers | Consumer Services | US |
| 2026-05-28 | GRIP Outreach For Youthwww.gripyouth.com | Education | US |
| 2026-06-03 | Unique Litho, Incuniquelitho.com | Manufacturing | US |
| 2026-06-07 | A A*** G*** A*S* | Not Found | |
| 2026-06-06 | A ASIA STRATEGIC | Business Services | |
| 2026-05-23 | First Mutual Holdingswww.firstmutual.co.zw | Financial Services | ZW |
| 2026-05-15 | Krum Public Librarywww.krumlibrary.org | Public Sector | US |
| 2026-05-25 | B basatamfi | Not Found | EG |
| 2026-05-20 | R Red-Line | Not Found | US |
| 2026-05-18 | Q Qua****Pro | Not Found | |
| 2026-05-24 | la familia adualt day centerwww.lafamiliaadultdaycenter.com | Healthcare | US |
| 2026-05-22 | P Pat**** S.r.l | Not Found | |
| 2026-05-24 | S Si**** West J******* | Not Found | |
| 2026-05-21 | Bresme Madrid S.L.www.bresme.com/en | Business Services | ES |
| 2026-05-16 | Papa John's Egyptwww.papajohnsegypt.com | Hospitality and Tourism | EG |
| 2026-05-19 | Rawaj Consumer Financewww.rawaj-finance.com | Financial Services | EG |
| 2026-05-14 | Ueno Fine Chemicals Industry (Thailand), Ltd.ueno-fc.co.th | Manufacturing | TH |
| 2026-05-14 | Vantage Energy LLCwww.vantageenergy.com | Energy | US |
| 2026-05-18 | C C***r*o T**uc**n* | Not Found | |
| 2026-05-18 | M m***o*ul | Not Found | |
| 2026-05-08 | Huse Incorporatedhuseinc.com | Hospitality and Tourism | US |
| 2026-05-14 | TAKOSAN OTOMOBILwww.takosan.com.tr/en | Manufacturing | TR |
| 2026-04-27 | A A**** F***** Plas**** | Manufacturing | |
| 2026-04-27 | F Filter to A**** F***** Plas**** | Manufacturing | |
| 2026-04-25 | T The Country Club of Darien | Hospitality and Tourism | US |
| 2026-04-27 | P Progressive Oral Surgery & Implantology | Healthcare | US |
| 2026-04-27 | P P**g**s***e O*al S**g**y & I**la**ol**y | Healthcare | |
| 2026-04-27 | J J**es **l*o | Consumer Services | |
| 2026-04-17 | S Swansea Ambulance Corps | Healthcare | GB |
| 2026-04-25 | T The **u***y C*** o* **r**n | Not Found | |
| 2026-04-17 | S S***s*a A**ul***e C***s | Not Found | |
| 2026-04-05 | D-Troy Logisticswww.dtroylogistics.com | Transportation/Logistics | MX |
| 2026-04-02 | BK Tomorrowwww.bktomorrow.com/en | Not Found | US |
| 2026-04-06 | Sahara Air Productssaharahenderson.com | Manufacturing | US |
| 2026-04-07 | * *W* **L LLC | Not Found | |
| 2026-04-05 | Cabinet d’Étude en Sécurité Pyrotechniquewww.cespyro.com | Business Services | FR |

