Emerging Threat Actor: NightSpire Ransomware
ID: 33d46c5f-bfe2-525c-adeb-fbfd1c930c01
STIX ID: report--33d46c5f-bfe2-525c-adeb-fbfd1c930c01
Feed Name: Halcyon Blog
NightSpire is an active, closed ransomware group first observed in early 2025 that performs surgical double-extortion attacks against mid-sized organizations (notably in professional services, healthcare, real estate, and manufacturing). They use phishing, stolen RDP credentials, and vulnerable edge apps for initial access, employ credential theft (Mimikatz), lateral movement (PsExec, WMI), and deployment techniques that include PowerShell and scripts; they encrypt Windows systems with AES-256 wrapped by RSA-2048, delete VSS snapshots, and publish stolen data on a Tor-based leak site, with reported ransoms between $150K and $2M and roughly 25–30 victims to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
