Emulating the Persuasive NightSpire Ransomware
ID: f210cae5-25f2-57dd-94e0-8efb2e4edfd5
STIX ID: report--f210cae5-25f2-57dd-94e0-8efb2e4edfd5
Feed Name: Security Boulevard
NightSpire is a financially motivated ransomware group that employs double extortion via a dedicated leak site, uses a Go-based ransomware binary that appends ".nspire" and employs hybrid partial/full encryption (AES-256/RSA-2048), leverages living-off-the-land techniques and credential dumping (e.g., Mimikatz), has abused CVE-2024-55591 in FortiOS, and recently announced a transition to an affiliate RaaS model—AttackIQ released emulation scenarios to validate defenses against these behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
