216.73.216.226

Leveling Up with NightSpire Ransomware

· Published 08/04/2026 09:15 · Modified 08/04/2026 11:01

Export JSON

Essential information

Published
08/04/2026 09:15
Modified
08/04/2026 11:01
Tags
2026-04-08 anydesk chrome remoting desktop data exfiltration file-encryption megasync nightspire persistence mechanisms raas ransomware-as-a-service remote desktop
Related entities
2 observables, 1 intrusion sets (apt), 16 techniques (mitre), 1 malware

Description

ransomware, first discovered in February 2025, presents a categorization challenge regarding whether it operates as (). Analysis of two incidents from December 2025 and March 2026 reveals significant variations in tactics, techniques, and procedures between attacks. The March 2026 incident involved threat actors installing and for persistence, using Everything and 7Zip for data staging, for exfiltration, and deploying VMWare Workstation and WPS Office. The attacker accessed systems via RDP days before detection. Comparison with the December 2025 incident shows evolution in the ransomware encryptor, including modified ransom note filenames and contents. These variations in TTPs and indicators suggest either operational evolution or involvement of multiple affiliates, demonstrating that ransomware indicators aren't consistent across campaigns.

External references