NightSpire is an emerging ransomware family and associated extortion operation first observed in early 2025. It evolved from exfiltration-focused extortion into a double-extortion model in which operators steal data and then encrypt victim systems while threatening public disclosure of stolen information. The malware has been described as a Go-based encryptor that traverses accessible drives, appends a distinctive encrypted-file extension in some observed cases, drops ransom notes, and can also encrypt OneDrive-hosted files without changing their extensions.
Observed intrusions indicate that NightSpire commonly gains initial access through exposed or compromised Remote Desktop Protocol access, and reporting also links the group to exploitation of Fortinet edge-device vulnerabilities such as CVE-2024-55591 for initial access in some campaigns. Rather than relying primarily on bespoke backdoors, operators have repeatedly used legitimate remote administration tools to maintain access and persistence, including Chrome Remote Desktop and AnyDesk. Post-compromise activity has included file discovery with common administrative utilities, compression of targeted data into archives, and exfiltration to cloud storage services before encryption. Multiple investigations also note variation in tooling, ransom-note formats, and encryptor samples across incidents, suggesting ongoing malware development or possible affiliate-driven operational differences.
NightSpire has targeted a broad range of sectors, including healthcare, education, government, finance, manufacturing, hospitality, logistics, and IT services, with victims reported across dozens of countries and a notable concentration in the United States. Industrial reporting also places the group among ransomware actors affecting manufacturing and other industrial organizations. Public reporting variously characterizes NightSpire as a closed-group operation and, in some accounts, as operating in a RaaS-like manner; the group’s exact operating model is therefore not fully settled. High-confidence reporting supports that it is an active ransomware threat using data theft, encryption, and public-leak pressure to extort organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Specifically, the group has exploited CVE-2024-55591, a FortiOS zero-day vulnerability from late last year which allows an unauthorized attacker to gain super-admin access to a Fortigate firewall appliance without supplying valid credentials.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware Signature: Trojan-Ransom."Nightspire" ... Ransomware/Win."Nightspire".C5769860 Ransomware/Win."Nightspire".C5775165
13 distinct techniques documented for this family, organized by ATT&CK tactic.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation whose industrial victim claims declined sharply in Q2 2026.
A Go-based ransomware family that uses double extortion: attackers steal sensitive files, exfiltrate them, then encrypt victim systems and threaten to publish stolen data on a Tor-based leak site if payment is not made. It appends the .nspire extension to encrypted files, drops ransom notes, and has been observed encrypting OneDrive files without changing their extensions.
A closed-group ransomware operation with OneDrive cloud encryption capability and exploitation tied to FortiGate access.
A ransomware family first reported in February 2025. The content discusses uncertainty over whether it operates as RaaS or as a closed in-house operation. Observed activity included RDP access, persistence via Chrome Remote Desktop and AnyDesk, use of Everything and 7Zip for staging, MEGASync for exfiltration, and deployment of a file encryptor that used extensions such as .nspire and ransom notes including _nightspire_readme.txt and [nspire_msg].txt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.