NightSpire is a financially motivated ransomware and extortion group active since at least March 2025. It is assessed as an emerging operation with comparatively low sophistication and weak operational security, but one that has nevertheless expanded its victim volume and maintained sustained activity through 2026. Reporting indicates NightSpire has targeted organizations opportunistically across multiple sectors and geographies, with a notable concentration on small and medium-sized organizations and recurring victimization in manufacturing, business services, healthcare, education, finance, consumer services, and energy. Victims have been observed in the United States, Europe, and the Middle East/North Africa, among other regions. NightSpire is associated with data theft, extortion, and more recently double extortion, combining exfiltration with encryption of victim data. The group has operated a leak site used to publish victim names and stolen information and to pressure non-paying organizations through public shaming and threats to sell or release data. Reported coercive tactics include short payment deadlines and direct outreach to employees during negotiations. Some reporting describes the operation as a closed group, while other reporting notes that its exact operating model remains unclear and does not conclusively establish whether it functions as a ransomware-as-a-service program. Observed tradecraft includes exploitation of internet-facing perimeter technologies for initial access, particularly Fortinet appliances. NightSpire has been linked to exploitation of CVE-2024-55591 in FortiOS and FortiProxy to obtain privileged access and enable lateral movement. For post-compromise activity, the group has used legitimate tools and LOLBins for reconnaissance, staging, defense evasion, compression, and exfiltration, including common administrative and file-transfer utilities and cloud-storage tooling. Reporting also notes OneDrive-based cloud encryption capability. NightSpire has been linked by multiple indicators of behavior and actor overlap to the little-known Rbfs ransomware group and is assessed as a likely rebrand or continuation of that operation. This assessment is based on shared operator personas, overlapping victims, and the disappearance of Rbfs branding as NightSpire emerged. Personas associated with promotion of both brands include xdragon128 and cuteliyuan, which have been identified as likely operators or affiliates involved in recruitment and victim advertising on cybercrime forums. By 2026, NightSpire was being tracked as a growing ransomware actor, with reporting showing sharp quarter-over-quarter expansion followed by fluctuations in monthly victim counts. It has been listed among active ransomware groups in global leak-site monitoring and first-quarter and monthly ransomware trend reporting, indicating that despite its relative immaturity, it became a visible participant in the broader ransomware ecosystem during 2025 and 2026. Known aliases and related names include nightspire, NightSpire, and the likely predecessor or associated group Rbfs.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Cedar Crest College.
Conducting a ransomware attack against PCCC Realty LLC.
Conducting a ransomware attack against Artistic Smiles in the United States.
Conducting a ransomware attack against a U.S. energy-sector company, legendsmn (Blue Ox, Paul Bunyan, Lumberjack Electric).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.