logo

NightSpire Ransomware Abuses RDP for Stealthy Persistence

ID: 456a7fc8-42cd-5f2e-bc49-d0d43b7ea552

STIX ID: report--456a7fc8-42cd-5f2e-bc49-d0d43b7ea552

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

NightSpire is an emerging cross-platform ransomware campaign (observed March–June 2025) that uses double-extortion: operators exfiltrate sensitive files (compressed with 7-Zip and uploaded via MEGAsync/MEGA) then encrypt victims' systems with a Go-based encryptor that appends ".nspire" and targets OneDrive-synced files. The group abuses legitimate remote-admin tools (Chrome Remote Desktop, AnyDesk) and RDP for stealthy persistence and access, impacting at least 64 organizations across 33 countries in healthcare, government, finance, manufacturing, and IT services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.