NightSpire Ransomware Uses RDP Access and Remote Admin Tools for Stealthy Persistence
ID: 1a61218a-7cd4-543f-8bf5-0fc4cca48cb9
STIX ID: report--1a61218a-7cd4-543f-8bf5-0fc4cca48cb9
Feed Name: cybersecurityNews.com
NightSpire is an active double‑extortion ransomware campaign observed targeting at least 64 organizations across 33 countries; operators gain initial access via RDP, deploy trusted remote‑access software (Chrome Remote Desktop, AnyDesk) for persistence, exfiltrate data using Everything/7‑Zip and MEGAsync, then run a Go‑based encryptor that appends .nspire and drops ransom notes. The report provides IoCs (file hashes, note filenames, email, paths), attack chain details, and mitigation recommendations such as restricting RDP, enforcing MFA, and monitoring unexpected remote access and cloud sync activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
