logo

NightSpire Ransomware Uses RDP Access and Remote Admin Tools for Stealthy Persistence

ID: 1a61218a-7cd4-543f-8bf5-0fc4cca48cb9

STIX ID: report--1a61218a-7cd4-543f-8bf5-0fc4cca48cb9

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Tushar Subhra Dutta

...
...

NightSpire is an active double‑extortion ransomware campaign observed targeting at least 64 organizations across 33 countries; operators gain initial access via RDP, deploy trusted remote‑access software (Chrome Remote Desktop, AnyDesk) for persistence, exfiltrate data using Everything/7‑Zip and MEGAsync, then run a Go‑based encryptor that appends .nspire and drops ransom notes. The report provides IoCs (file hashes, note filenames, email, paths), attack chain details, and mitigation recommendations such as restricting RDP, enforcing MFA, and monitoring unexpected remote access and cloud sync activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.