logo

Emerging Threat Actor: NightSpire Ransomware

ID: 33d46c5f-bfe2-525c-adeb-fbfd1c930c01

STIX ID: report--33d46c5f-bfe2-525c-adeb-fbfd1c930c01

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2025-07-01

Date Updated: 2026-04-28

...
...

NightSpire is an active, closed ransomware group first observed in early 2025 that performs surgical double-extortion attacks against mid-sized organizations (notably in professional services, healthcare, real estate, and manufacturing). They use phishing, stolen RDP credentials, and vulnerable edge apps for initial access, employ credential theft (Mimikatz), lateral movement (PsExec, WMI), and deployment techniques that include PowerShell and scripts; they encrypt Windows systems with AES-256 wrapped by RSA-2048, delete VSS snapshots, and publish stolen data on a Tor-based leak site, with reported ransoms between $150K and $2M and roughly 25–30 victims to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.