NightSky is a Windows ransomware family active by at least 2021–2022 and associated in multiple reporting streams with China-linked cybercriminal activity. It has been discussed alongside ransomware operations such as Cheers and has also appeared in broader clustering of China-nexus intrusion activity that reused shared tooling, including HUI Loader variants. NightSky has additionally been cited in relationship mapping of ransomware groups where affiliate overlap, rebranding, and operator connections complicate attribution.
Technically, NightSky is assessed with high confidence to be closely derived from Rook ransomware, likely as a fork. Comparative reverse engineering found extensive similarity in cryptographic implementation, threading, synchronization, and file-encryption workflow, beyond what would be expected from incidental overlap. Both families use statically linked Mbed TLS code and implement a hybrid encryption design in which the malware generates a victim RSA-2048 key pair, encrypts the victim private key with an embedded attacker-controlled RSA-2048 public key, and generates a unique 16-byte AES key per file that is then encrypted with the victim public key and stored in the encrypted file footer. NightSky differs from Rook in some implementation details, notably using AES-128-CBC with a hardcoded IV, while preserving a highly similar encrypted-file structure and overall logic. Analysis has also noted that NightSky samples were protected with VMProtect, increasing reverse-engineering difficulty.
NightSky’s known behavior is consistent with enterprise-targeting ransomware used for data theft and extortion. It encrypts files on compromised Windows systems and has been referenced in reporting focused on double-extortion ecosystems and leak-site activity. It has also been observed in operational contexts involving malware loaders used to stage later payloads, indicating use within broader post-compromise intrusion chains rather than as a purely standalone commodity encryptor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NightSky is a ransomware family referenced as part of BRONZE STARLIGHT-linked operations that also used HUI Loader variants.
Ransomware group mentioned alongside Cheers as reportedly backed by a China-based cybercrime group.
周辺グループとの関係性から、特定国家への帰属可能性を示唆する事例として挙げられているランサムウェア。
Mentioned only in passing as another ransomware strain used for comparison when discussing similarities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.