NightSpire Ransomware Attack Chain, Tools and Tactics
| May 23, 2026
Key Takeaways
- NightSpire is a ransomware family first identified in early 2025 using double extortion, stealing files before encryption and threatening to leak them on a Tor-based site if victims refuse to pay.
- Between March and June 2025, NightSpire hit at least 64 organizations across 33 countries, with the U.S. leading the victim list, followed by Turkey, Hong Kong, Japan, Taiwan, Mexico, Spain, and Egypt.
- The encryptor is a Go-based executable. It scans directories, appends the .nspire extension to affected files, and drops a ransom note in every folder with encrypted content.
- Operators use legitimate tools for stealth, including Chrome Remote Desktop and AnyDesk for persistence, Everything for file discovery, 7-Zip for archiving, and MEGAsync for exfiltration to MEGA cloud storage.
- You validate your defenses against NightSpire using the Picus Security Validation Platform, which includes threats 79926 (NightSpire Ransomware Download Threat) and 95001 (NightSpire Ransomware Email Threat) in the Picus Threat Library.
NightSpire is an emerging ransomware family first identified in early 2025, employing traditional double extortion techniques: sensitive files are stolen before encryption takes place, and in case of refusal of ransom, the criminals threaten to dump the stolen files on their Tor-based leak website. While impact distribution is global, the U.S. tops the list, followed by Turkey, Hong Kong, Japan, Taiwan, Mexico, Spain, and Egypt [1].
In just the three months between March and June 2025, the threat actors have already compromised at least 64 organizations across 33 countries by mid-2025. The attacks target a broad array of industries, from healthcare, education, and governmental institutions, to finance, manufacturing, hospitality, IT services, and logistics.
The encryption itself is executed via an executable written in Go. The application scans directories, appends the .nspire file extension to all impacted files, and places a ransom message within each affected folder. What should be highlighted here is that the malware goes beyond regular local directories and also encrypts OneDrive files on their way to the cloud storage service.
In this blog, you will learn how NightSpire operates, which tools and techniques the attackers use across the intrusion chain, and how to validate your defenses against this threat.
How Does NightSpire Ransomware Work?
Persistence Through Remote Access Tools
In the March 2026 intrusion, the threat actor reached an endpoint over Remote Desktop Protocol (RDP) [2].
Instead of building its own persistence mechanisms, the attacker relied on remote administration programs that were installed to facilitate ongoing access.
For instance, Chrome Remote Desktop was deployed on at least two compromised machines. The malware created a persistent Windows service named "Chrome Remote Desktop Service," which ran using the following command:
|
"C:\Program Files (x86)\Google\Chrome Remote Desktop\147.0.7727.3\remoting_host.exe" --type=daemon --host-config="C:\ProgramData\Google\Chrome Remo..." |
The Google account tied to this deployment was prince1990905@gmail[.]com [2].
On a separate endpoint, AnyDesk was used. In this case, it created both a Windows service ("AnyDesk Service") and a shortcut (anydesk.lnk) in the Startup folder to enable auto-starting upon boot-up.
|
"C:\Program Files (x86)\AnyDesk\AnyDesk.exe" --service |
Usage of legitimate tools gave the threat actors an extra layer of stealth.
Discovery, Data Collection and Exfiltration
Upon establishing footholds, the actor introduced a range of freely available utilities for discovering and collecting sensitive data. The tools are explained below:
- Everything (voidtools): It is a file discovery tool that allows scanning entire drives for files in just a few moments. After launching the utility, the attacker used its graphical user interface to search and discover files.
- 7-Zip: It was used to compress selected folders from targeted folders to archives and reduce the total number of files that need to be exfiltrated.
- MEGAsync was run on the compromised endpoint to transfer the staged 7-Zip archives to the MEGA cloud storage service.
The example commands which attacker might run are given below:
|
# Launch Everything to search the file system |
Execution and Encryption
The NightSpire encryptor is a portable executable written in Go [3]. Go binaries are statically linked and ship with their own runtime, which has two consequences worth noting:
- The same source can be compiled for Windows, Linux, and macOS with minimal effort, giving operators cross-platform flexibility.
- The compiled binaries are relatively large and contain characteristic strings that make the language easy to identify from static analysis.
On execution, the encryptor immediately opens a console window using conhost.exe (the standard Windows host process for console applications) and begins enumerating directories on the system. During this pass, it walks through every accessible drive letter and path it can see, building the list of files it will encrypt.
Each encrypted file is renamed with a .nspire extension appended to the original filename. A ransom note is written into every directory that contains encrypted files.
In the ransom note, the threat actor indicated that they also encrypted OneDrive files [3]:
|
Hi, Your hotel is hacked! ... |
How Picus Simulates NightSpire Ransomware Attacks?
We also strongly suggest simulating NightSpire Ransomware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against hundreds of other ransomware variants, such as Warlock, BlackCat, Black Basta, and Akira, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the NightSpire Ransomware Attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
79926 |
NightSpire Ransomware Download Threat |
Network Infiltration |
|
95001 |
NightSpire Ransomware Email Threat |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.
References
[1] “NightSpire Ransomware.” Accessed: Apr. 22, 2026. [Online]. Available: https://www.broadcom.com/support/security-center/protection-bulletin/nightspire-ransomware
[2] H. Carvey and L. O'Donnell-Welch, "Decoding NightSpire: Ransomware IOCs aren't set in stone," Huntress, Apr. 22, 2026. [Online]. Available: https://www.huntress.com/blog/nightspire-ransomware
[3] "NightSpire ransomware encrypts cloud-stored OneDrive files," SonicWall, Apr. 22, 2026. [Online]. Available: https://www.sonicwall.com/blog/nightspire-ransomware-encrypts-onedrive-files
