Skip to main content
Mallory
Exploits CVEs in the wild

NightSpire

Also known asNightSpire

NightSpire is a ransomware threat group first observed in February 2025. Reporting in the provided content describes it as initially focused on data theft and extortion, later evolving from exfiltration-only extortion to double extortion, including encryption after theft. It is also described as a closed-group operation and has been noted for OneDrive cloud encryption capability. The group operated a leak site by March 12, 2025 and used ProtonMail, OnionMail, Telegram, qTox, and Tor hidden services for victim communications; one ransom note used the contact address nightspireteam.receiver@onionmail.org and stated that OneDrive files were also locked without changing their extensions. The content links NightSpire to exploit-driven access and names WinSCP and Everything.exe among tools associated with rising groups including NightSpire. VulnCheck associates NightSpire with exploitation of Fortinet FortiOS CVE-2024-55591, alongside DragonForce, Hunters International, Qilin, RansomHub, and SuperBlack. Broader reporting in the content also places NightSpire among groups active in the first half of 2025 and among emerging groups whose activity increased sharply in March 2026. Victimology in the provided content indicates a primary focus on U.S. targets, with additional activity in Europe and against small and medium-sized enterprises. Specifically mentioned victims or claimed victims include Hyatt Place Chelsea New York hotel, Commune d’Ardon in France, Green Flame Gas Co in Kuwait, CAMI in the United States, and Nippon Ceramic. The Hyatt-related reporting states NightSpire allegedly leaked 48.5 GB of data from the Hyatt Place Chelsea New York hotel. Other cited victim lists include Hydro Vacuum, Baily International of Atlanta, Tophe, Raja Ferry Port Public, Far East Consortium International, Business Ledger Limited, and Tanaka Holdings. The content consistently characterizes NightSpire as a ransomware/extortion operation; no nation-state attribution is provided.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics29 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589×2
Gather Victim Identity Information
TA0001
Initial Access
2 techniques
T1133×2
External Remote Services
T1190
Exploit Public-Facing Application
TA0002
Execution
2 techniques
T1047
Windows Management Instrumentation
T1569
System Services
T1569.002
Service Execution
TA0003
Persistence
3 techniques
T1133×2
External Remote Services
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.009
Shortcut Modification
TA0004
Privilege Escalation
2 techniques
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.009
Shortcut Modification
TA0007
Discovery
1 technique
T1083×2
File and Directory Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.001×2
Remote Desktop Protocol
TA0009
Collection
3 techniques
T1005
Data from Local System
T1074
Data Staged
T1560
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
1 technique
T1219
Remote Access Tools
TA0010
Exfiltration
3 techniques
T1020×3
Automated Exfiltration
T1041×3
Exfiltration Over C2 Channel
T1567×4
Exfiltration Over Web Service
T1567.002×2
Exfiltration to Cloud Storage
TA0040
Impact
2 techniques
T1486×7
Data Encrypted for Impact
T1657×3
Financial Theft
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping20

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

NightSpire | Mallory