logo

Emulating the Persuasive NightSpire Ransomware

ID: f210cae5-25f2-57dd-94e0-8efb2e4edfd5

STIX ID: report--f210cae5-25f2-57dd-94e0-8efb2e4edfd5

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Ayelen Torello

...
...

NightSpire is a financially motivated ransomware group that employs double extortion via a dedicated leak site, uses a Go-based ransomware binary that appends ".nspire" and employs hybrid partial/full encryption (AES-256/RSA-2048), leverages living-off-the-land techniques and credential dumping (e.g., Mimikatz), has abused CVE-2024-55591 in FortiOS, and recently announced a transition to an affiliate RaaS model—AttackIQ released emulation scenarios to validate defenses against these behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.