NightSpire is a financially motivated ransomware and data-extortion operation that emerged in early 2025. The operation encrypts victim systems, steals data before encryption and threatens to publish the material through a Tor-based data leak site if the victim does not pay. Encrypted files typically receive the .nspire extension, and observed ransom-note filenames include _nightspire_readme.txt, [nspire_msg].txt and nightspire_readme.txt.
NightSpire initially appeared to operate as a closed group rather than a public ransomware-as-a-service program. In 2026, however, the operation announced that it was transitioning to a RaaS model. The change coincided with a substantial increase in victims posted to its leak site. MOXFIVE reported that NightSpire had listed more than 200 organizations by May 2026, including approximately 150 during the first four months of the year.
There is high confidence that NightSpire represents an active ransomware ecosystem rather than merely a leak-site brand. Multiple security companies have independently analyzed NightSpire encryptors, ransom notes and intrusion activity. There is only moderate confidence, however, that every incident attributed to NightSpire was conducted by the same operators. The reported transition to RaaS, combined with significant differences between observed intrusions, indicates that affiliates or separate intrusion teams may now deploy the NightSpire payload under a shared extortion brand.
Activity and targeting
NightSpire has claimed victims across North America, Europe and Asia and does not appear to restrict its activity to a particular country or political objective. The United States has accounted for the largest reported concentration of victims, followed by countries including France, India, Hong Kong and Japan. Manufacturing and production organizations have been particularly prominent, although the operation has also affected technology, healthcare, retail, hospitality, construction, financial services, education and professional-services organizations.
The breadth of its victim set is consistent with opportunistic financial targeting rather than a narrowly defined strategic campaign. NightSpire actors appear to favor organizations with exposed remote-access services, vulnerable edge devices or compromised administrative credentials. The operation’s selection of victims across unrelated sectors and countries suggests that access availability and the perceived value of the victim’s data are more important than industry or geography.
There is high confidence that NightSpire is financially motivated. Its ransom notes, negotiation channels, countdown-based leak site and use of double extortion all support a conventional cybercriminal objective. There is low confidence in any more specific geographic attribution. Public reporting has not established where the core operators are located, their nationality or whether they have meaningful connections to another established ransomware organization.
Victim totals should be treated as a measure of public claims rather than confirmed compromises. A listing on NightSpire’s leak site indicates that the group claims to possess data associated with the named organization, but it does not independently establish how the data was obtained, whether encryption occurred or whether the organization experienced a material operational disruption. Confidence in individual claims therefore depends on corroboration from the victim, an incident-response provider or verifiable samples of stolen material.
Methods and operational characteristics
NightSpire intrusions have begun through compromised credentials and exploitation of internet-facing infrastructure. Reported access paths include Remote Desktop Protocol, VPN portals and firewall-management interfaces. Researchers have associated some activity with exploitation of CVE-2024-55591, an authentication-bypass vulnerability affecting FortiOS and FortiProxy management interfaces. There is moderate confidence that NightSpire actors exploited this vulnerability in at least some incidents, but it should not be treated as a universal entry vector for the operation.
Once inside a network, NightSpire-associated actors have used both native Windows capabilities and commercially available administrative tools. Reported techniques include PowerShell and Windows Management Instrumentation for execution, Mimikatz for credential theft, PsExec for remote execution and Advanced IP Scanner for network discovery. AnyDesk and Chrome Remote Desktop have been installed to preserve interactive access.
Collection and exfiltration activity has included Everything Search to identify files, 7-Zip to create archives and MEGASync, MEGACmd, WinSCP or Rclone to transfer data. In a March 2026 intrusion investigated by Huntress, the attacker entered through RDP, installed Chrome Remote Desktop, searched for files with Everything, archived selected material with 7-Zip and apparently used MEGASync for exfiltration before launching the NightSpire encryptor.
The same intrusion illustrates why NightSpire should not be assigned a single rigid set of indicators or procedures. Huntress found meaningful differences between NightSpire incidents observed in December 2025 and March 2026, including changes to the encryptor and ransom-note format. The later attacker also imported numerous graphical tools rather than relying primarily on native system utilities. These differences could reflect continuing development by a single operator, but they are also compatible with deployment by different affiliates.
There is high confidence that the .nspire extension and NightSpire-branded ransom notes are reliable indicators of payload deployment. There is only moderate confidence that tools such as AnyDesk, 7-Zip, MEGASync, PsExec or Mimikatz distinguish NightSpire from other ransomware operations because these utilities are widely used by unrelated threat actors. Defenders should therefore prioritize behavioral sequences and intrusion context over isolated filenames, hashes or legitimate remote-administration tools.
The NightSpire encryptor analyzed by AhnLab used AES for file encryption and protected the encryption material with an RSA public key. It applied partial or block encryption to large file types—including virtual disks, database files, archives and backup-related formats—to reduce the time required to make them unusable. Other files were fully encrypted. This approach allows the ransomware to disrupt large storage environments more rapidly than encrypting every byte of every file.
NightSpire’s extortion infrastructure uses countdown timers, threatening language and several communication channels, including privacy-focused email services, Telegram and, in some cases, ordinary email accounts. The use of public or readily attributable services may indicate uneven operational security. It also reinforces the assessment that NightSpire is an evolving criminal enterprise whose affiliates or operators may possess significantly different levels of sophistication.
What type of group is it?
NightSpire is best described as a financially motivated ransomware and data-extortion operation, with high confidence. It is not known to pursue a political, ideological or state-directed objective, and its broad targeting pattern is more consistent with maximizing ransom opportunities.
There is moderate confidence that NightSpire now functions as a RaaS ecosystem. The operation publicly announced a move toward that model, and the rapid increase in claimed victims and variation between intrusions are consistent with affiliate participation. Public evidence does not yet establish how formal the program is, how many affiliates have joined or whether the core operators still conduct some intrusions themselves.
There is low confidence in treating “NightSpire” as a single stable intrusion group. The name may refer simultaneously to the ransomware developers, leak-site administrators, negotiators and multiple operators who obtain access and deploy the payload. Attribution should therefore distinguish between a NightSpire-branded attack, which can often be established from the encryptor and ransom note, and an intrusion conducted by NightSpire’s core personnel, which generally cannot be determined from public evidence.
There is also low confidence in claims that NightSpire is a rebrand or successor to another ransomware operation. Similarities in tooling, extortion practices and malware design are not sufficient to establish shared personnel because those characteristics are common throughout the ransomware ecosystem. No authoritative public research currently provides a strong technical or organizational link to a predecessor group.