Warning About NightSpire Ransomware Following Cases of Damage in South Korea
Sept. 1, 2025, 10:34 a.m.
Description
NightSpire, a ransomware group active since February 2025, employs an aggressive strategy and specialized infrastructure similar to Ransomware-as-a-Service models. They operate a Dedicated Leak Site, posting victim information and countdown timers for data release. Using highly threatening language, NightSpire offers various communication channels for negotiations. The group targets corporations across multiple countries and industries, employing a double-extortion strategy of encrypting and leaking data. NightSpire ransomware uses block encryption for specific file types and full encryption for others, adding the .nspire extension to encrypted files. The ransomware inserts the AES symmetric key at the end of encrypted files, further secured by RSA public key encryption.
Tags
Date
- Created: Sept. 1, 2025, 9:53 a.m.
- Published: Sept. 1, 2025, 9:53 a.m.
- Modified: Sept. 1, 2025, 10:34 a.m.
Indicators
- d5f9595abb54947a6b0f8a55428ca95e6402d2aeb72cbc109beca457555a99a6
- 32e10dc9fe935d7c835530be214142041b6aa25ee32c62648dea124401137ea5
Additional Informations
- Maritime
- Construction
- Retail
- Chemical
- Technology
- Finance
- Manufacturing
- Hong Kong
- Taiwan
- China
- Poland
- Thailand
- Japan
- United Kingdom of Great Britain and Northern Ireland
- United States of America