HackerFeeds
All ransomware groups

nightspire

296 tracked victims
·first seen 2025-02-17·last activity 2026-06-19

Group profile

NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing, healthcare, finance, and education sectors in the US, France, India, Taiwan, and Japan, using aggressive double-extortion with ransom deadlines as short as two days.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Compromised RDP credentials used for initial access.

  • T1110Brute Force

    Brute-forcing remote login credentials (RDP) and MFA fatigue attacks.

  • T1190Exploit Public-Facing Application

    Exploitation of CVE-2024-55591 — FortiOS/FortiProxy authentication bypass; unauthenticated attackers gain super-admin privileges via crafted POST requests to /api/v2/cmdb/.

  • T1566Phishing

    Malicious attachments and drive-by downloads.

TA0002

Execution

  • T1059Command and Scripting Interpreter

    PowerShell scripts, batch files, PsExec, WMI; conhost.exe command execution window.

  • T1072Software Deployment Tools

    Abuse of legitimate tools (WinSCP, MEGACmd, 7-Zip, PsExec) across the attack chain.

TA0003

Persistence

  • T1053Scheduled Task/Job

    Persistence via Windows Task Scheduler; service creation and modification.

  • T1136Create Account

    Administrative account creation post-exploitation on FortiGate devices.

  • T1547Boot or Logon Autostart Execution

    Reboot persistence mechanisms.

  • T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

    Persistence via HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and RunOnce.

TA0004

Privilege Escalation

  • T1068Exploitation for Privilege Escalation

    FortiOS super-admin access via CVE-2024-55591 exploitation.

TA0005

Defense Evasion

  • T1027Obfuscated Files or Information

    Obfuscation techniques to evade analysis.

  • T1036Masquerading

    Renamed processes and use of legitimate tools (WinSCP, MEGACmd, 7-Zip, PsExec) blending into normal operations.

  • T1070Indicator Removal

    Removal of forensic indicators from compromised systems.

  • T1218System Binary Proxy Execution

    Execution via legitimate system binaries (LOLBins) to evade detection.

TA0006

Credential Access

  • T1003OS Credential Dumping

    Credential dumping via Mimikatz.

  • T1003.001OS Credential Dumping: LSASS Memory

    LSASS memory extraction for credential harvesting.

  • T1552Unsecured Credentials

    Harvesting of stored credentials within the environment.

TA0007

Discovery

  • T1046Network Service Discovery

    Network scanning to map internal infrastructure using Advanced IP Scanner.

  • T1057Process Discovery

    Process enumeration on compromised systems.

  • T1082System Information Discovery

    Collection of system details from compromised hosts.

  • T1083File and Directory Discovery

    File indexing and enumeration using Everything.exe.

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    RDP-based lateral movement across compromised network.

  • T1021.002Remote Services: SMB/Windows Admin Shares

    Lateral movement via PsExec over SMB.

  • T1047Windows Management Instrumentation

    WMI-based execution and lateral movement.

TA0009

Collection

  • T1119Automated Collection

    Automated sensitive data gathering from compromised systems.

  • T1560Archive Collected Data

    Compression of collected data using 7-Zip (7z2408-x64.exe) prior to exfiltration.

  • T1560.001Archive Collected Data: Archive via Utility

    7-Zip archiving of stolen data prior to exfiltration.

TA0010

Exfiltration

  • T1041Exfiltration Over C2 Channel

    Data exfiltration over C2 channel.

  • T1048Exfiltration Over Alternative Protocol

    Data exfiltration via WinSCP (v6.3.7) and Rclone over encrypted channels.

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    MEGACmd used to upload stolen data to MEGA cloud storage. Documented exfiltration of 1.5TB from a single healthcare victim.

TA0011

Command and Control

  • T1071Application Layer Protocol

    Standard web protocols and Tor-based communication. Multi-channel comms: ProtonMail, OnionMail, Gmail, Telegram, qTox.

  • T1573Encrypted Channel

    Asymmetric encrypted non-C2 protocols used to evade IDS.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Hybrid AES-256 (file content) + RSA-2048 (key protection) encryption; appends .nspire extension; processes files in 1MB block chunks. Double extortion model — data theft + encryption.

TA0042

Resource Development

  • T1587Develop Capabilities

    Custom Go-based ransomware development with modular architecture.

Recent victims

showing 50 of 296
DateWebsite / victimSectorCountry
2026-06-19
artisticsmiles.org
Artistic Smilesartisticsmiles.org
Consumer ServicesUS
2026-06-17
legendsmn.com
legendsmn(Blue Ox, Paul Bunyan, Lumberjack Electric)legendsmn.com
EnergyUS
2026-05-31
deancosmeticdentistry.com
dean cosmetic dentistrydeancosmeticdentistry.com
HealthcareUS
2026-06-01
G
Guy E******* & F*******, P.A
Financial Services
2026-06-16
C
Central Texas ***** *****
Not Found
2026-06-16
R
Ri***** Co**** Europe S.r.l.
Not Found
2026-06-05
B
B****S I******t***l
Business Services
2026-06-02Hospitality and TourismEG
2026-06-13
G
G**** R****l*e
Not Found
2026-05-27Public SectorUS
2026-05-29
kcmn.us
K****** County. Mi**e**takcmn.us
Public SectorUS
2026-05-17
twaxworks.com
WaxWorks Incwww.twaxworks.com
Consumer ServicesUS
2026-05-27
bluenilemedical.com
Blue Nile Medical Centerbluenilemedical.com
HealthcareUS
2026-05-22
P
Pattono S.r.l
Business ServicesIT
2026-05-24
S
Sierra West Jewelers
Consumer ServicesUS
2026-05-28
gripyouth.com
GRIP Outreach For Youthwww.gripyouth.com
EducationUS
2026-06-03
uniquelitho.com
Unique Litho, Incuniquelitho.com
ManufacturingUS
2026-06-07
A
A*** G*** A*S*
Not Found
2026-06-06
A
ASIA STRATEGIC
Business Services
2026-05-23
firstmutual.co.zw
First Mutual Holdingswww.firstmutual.co.zw
Financial ServicesZW
2026-05-15
krumlibrary.org
Krum Public Librarywww.krumlibrary.org
Public SectorUS
2026-05-25
B
basatamfi
Not FoundEG
2026-05-20
R
Red-Line
Not FoundUS
2026-05-18
Q
Qua****Pro
Not Found
2026-05-24
lafamiliaadultdaycenter.com
la familia adualt day centerwww.lafamiliaadultdaycenter.com
HealthcareUS
2026-05-22
P
Pat**** S.r.l
Not Found
2026-05-24
S
Si**** West J*******
Not Found
2026-05-21
bresme.com
Bresme Madrid S.L.www.bresme.com/en
Business ServicesES
2026-05-16
papajohnsegypt.com
Papa John's Egyptwww.papajohnsegypt.com
Hospitality and TourismEG
2026-05-19
rawaj-finance.com
Rawaj Consumer Financewww.rawaj-finance.com
Financial ServicesEG
2026-05-14
ueno-fc.co.th
Ueno Fine Chemicals Industry (Thailand), Ltd.ueno-fc.co.th
ManufacturingTH
2026-05-14
vantageenergy.com
Vantage Energy LLCwww.vantageenergy.com
EnergyUS
2026-05-18
C
C***r*o T**uc**n*
Not Found
2026-05-18
M
m***o*ul
Not Found
2026-05-08
huseinc.com
Huse Incorporatedhuseinc.com
Hospitality and TourismUS
2026-05-14
takosan.com.tr
TAKOSAN OTOMOBILwww.takosan.com.tr/en
ManufacturingTR
2026-04-27
A
A**** F***** Plas****
Manufacturing
2026-04-27
F
Filter to A**** F***** Plas****
Manufacturing
2026-04-25
T
The Country Club of Darien
Hospitality and TourismUS
2026-04-27
P
Progressive Oral Surgery & Implantology
HealthcareUS
2026-04-27
P
P**g**s***e O*al S**g**y & I**la**ol**y
Healthcare
2026-04-27
J
J**es **l*o
Consumer Services
2026-04-17
S
Swansea Ambulance Corps
HealthcareGB
2026-04-25
T
The **u***y C*** o* **r**n
Not Found
2026-04-17
S
S***s*a A**ul***e C***s
Not Found
2026-04-05
dtroylogistics.com
D-Troy Logisticswww.dtroylogistics.com
Transportation/LogisticsMX
2026-04-02Not FoundUS
2026-04-06
saharahenderson.com
Sahara Air Productssaharahenderson.com
ManufacturingUS
2026-04-07
*
*W* **L LLC
Not Found
2026-04-05
cespyro.com
Cabinet d’Étude en Sécurité Pyrotechniquewww.cespyro.com
Business ServicesFR