Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

NightSpire Ransomware Decryption & Data Recovery

  • Active
  • High
  • No public decryptor

NightSpire is an emerging double-extortion crew active since February 2025, marked by the .nspire extension and a readme.txt note. It breaks in mainly through Fortinet appliance flaws and weak RDP, sets deadlines as short as 48 hours, and has no free public decryptor.

First seen
2025-02
File extensions
.nspire
Ransom notes
readme.txt
Affected platforms
Windows

Family profile

File extensions
  • .nspire
Ransom notes
  • readme.txt
  • _nightspire_readme.txt
  • [nspire_msg].txt
Contact patterns
  • Tor (.onion) leak site and negotiation portal (onion address begins with nspire)
  • qTox ID and a Telegram channel
  • Anonymous mail domains such as ProtonMail and OnionMail, plus observed Gmail addresses
  • A per-victim UUID inside the note, with an access password in some builds
Aliases / versions
NightSpire Ransomware、nspire
First seen
2025-02
Status
Active
Operational status
Newly emerged
Threat level
High
Affected platforms
  • Windows
Tags
  • Emerging
  • Active
  • Double extortion
  • Ransomware-as-a-Service
  • Exploits vulnerabilities
  • RDP brute force
  • Phishing
Decryptor
No public decryptor

There is no free public decryptor for NightSpire. No More Ransom, security vendors and law enforcement have released nothing for .nspire, and published analysis has not disclosed any exploitable flaw in its key generation or key handling.

One warning worth repeating: searching for a "NightSpire decryptor" surfaces commercial pages claiming they can decrypt .nspire files directly. Those are lead generation for recovery services; without the operators' private key there is no generic decryption algorithm. The realistic recovery routes are backups and snapshots, shadow copies, the intact regions left by block-based encryption of large files, and unencrypted copies plus log replay. Feasibility has to be measured on real samples rather than inferred from the extension.

We do not pay ransoms, do not negotiate on a client's behalf, and do not resell payment under the label of a "decryption tool".

Latest activity

  1. Ransomware.live tracks NightSpire past 320 named victims across 53 countries, with leak-site postings continuing into September 2026. Manufacturing leads, then technology, professional services, healthcare and retail.

    Sources
  2. Barracuda profiled NightSpire at 259 named victims, assessed it as a rebrand of the early-2025 Rbfs operation run by xdragon128 and cuteliyuan, and noted it began recruiting RaaS affiliates in April 2026.

    Sources
  3. Huntress detailed two NightSpire intrusions (Dec 2025, Mar 2026): stolen RDP credentials, Chrome Remote Desktop and AnyDesk persistence, note renamed to [nspire_msg].txt, and enc.exe rebuilt per operation.

    Sources

Overview

NightSpire was first observed in February 2025 and its dark-web leak site went live that March. It is one of the fastest-growing emerging double-extortion crews of the past two years. It began as a closed, self-run operation: intrusion, lateral movement, exfiltration and negotiation were all handled by core members, with no public affiliate programme. In April 2026 the group began openly recruiting affiliates on its leak site and announced a move to ransomware-as-a-service, which makes subsequent tradecraft more varied and harder to predict.

Barracuda's May 2026 profile assesses NightSpire as a rebrand of the short-lived Rbfs extortion operation from early 2025: the code differs, but personnel and infrastructure carry over, with publicly visible operator handles xdragon128 and cuteliyuan. Researchers also note weak operational security - browsable leak-site directories, a leaked server hostname, even consumer mail accounts used in negotiations. The profile is an aggressive crew with limited engineering maturity.

The scale is no longer small, though counts differ sharply between trackers. As of September 2026 ransomware.live records more than 320 named organisations across 53 countries; Barracuda's May 2026 profile gives 259. Manufacturing leads, followed by technology, professional services, healthcare and retail, and the most-affected countries are the United States, then India, Turkey, France and Taiwan. Halcyon reads the picture differently: it assesses that activity faded through the second quarter of 2026, describes the group as near-dormant by mid-year, and counts only 25 to 30 publicly named victims. This entry treats the group as still active because new leak-site listings continue to appear, but the sources genuinely conflict and no single figure should be taken as settled. Targets are mostly small and mid-sized organisations with broad external exposure and weak baselines - opportunistic selection, not vertical targeting.

For Chinese enterprises the relevant point is the entry path itself: known Fortinet edge-device vulnerabilities and weak RDP are exactly the exposures most common in manufacturing and cross-border branch networks. No public report confirms a campaign aimed at mainland China, but Asia-Pacific victim counts are substantial, and overseas subsidiaries sit squarely inside the target space.

How to identify it

Extension. The .nspire suffix is appended to the full original filename, so order.xlsx becomes order.xlsx.nspire. The base name is neither rewritten nor randomised.

Ransom note. A plain-text note is dropped in every directory containing encrypted files. Three filenames are publicly documented: readme.txt (the early, dominant form recorded by SonicWall and Proven Data), _nightspire_readme.txt (a December 2025 build per Huntress) and [nspire_msg].txt (a March 2026 build per Huntress; the square brackets come from a written description rather than a verified sample screenshot). The note carries a per-victim UUID and, in some builds, an access password for the Tor negotiation portal. The text stresses that data has already been copied out and sets a deadline as short as 48 hours.

An indicator that is easy to miss. The note explicitly claims that OneDrive files are encrypted too. NightSpire encrypts files in synced OneDrive folders without changing extensions or icons, so Explorer looks normal while the contents are already overwritten. Scoping an incident purely by counting .nspire files will therefore understate the damage badly.

Host artefacts. The encryptor is dropped by hand as an ordinary executable in a user-writable directory; the filename varies between operations and should not be treated as a fixed indicator. The same engagements show installs of Chrome Remote Desktop, AnyDesk, Everything (voidtools), 7-Zip and MEGAsync, and the incidents Huntress analysed also involved VMware Workstation and WPS Office. Because the encryptor is rebuilt per operation - Huntress compared December 2025 and March 2026 builds and found different hashes - hash-only detection is not sufficient.

Infection vectors

NightSpire relies on no zero-days; everything reduces to exposure plus credentials:

  • Edge-device vulnerabilities. Both 360 and Barracuda rank CVE-2024-55591, the FortiOS/FortiProxy authentication bypass, as the primary initial vector - successful exploitation yields super-admin access directly.
  • RDP. Brute-forced or credential-stuffed RDP is the other frequent path; the March 2026 incident analysed by Huntress began with stolen RDP credentials.
  • Phishing, MFA fatigue and RMM abuse. Used to get past accounts that do have multi-factor authentication.
  • Persistence. Chrome Remote Desktop and AnyDesk are installed as resident channels, which are harder to block outright than a custom backdoor.
  • Lateral movement and discovery. What recurs in first-hand incident analysis is file-search tooling such as Everything (voidtools), used to locate high-value data quickly. Credential-dumping and remote-execution utilities of the Mimikatz or PsExec type appear in aggregated write-ups but are not individually confirmed in the published case analyses - hunt for them as possible, not certain.
  • Exfiltration. 7-Zip archives uploaded through MEGA/MEGAsync, WinSCP and similar channels, establishing the double-extortion leverage.

The pattern is unmistakably hands-on-keyboard: operators dwell, verify hosts one by one, then detonate the encryptor at a chosen moment. The upside for responders is that such operations usually leave a rich, reconstructable log trail.

Encryption behavior

Encryptor. A single Go executable, statically linked with its own runtime. Every first-hand incident analysis available - Huntress, SonicWall, Barracuda and others - documents Windows samples only. Halcyon's profile describes Linux and ESXi variants as in development and not yet deployed, and commercial recovery-site claims about a "NightSpire ESXi encryptor" lack credible technical corroboration. This entry therefore lists Windows alone; risk to virtualised estates should be read as theoretically possible but unproven, not as evidence that a mature ESXi encryptor exists.

Algorithms. Public analysis describes a conventional hybrid scheme - a symmetric cipher for file content with RSA wrapping the file keys - commonly summarised as AES-256 plus RSA-2048, with some analyses also noting RC4/XOR-style obfuscation in the samples. The descriptions are not fully consistent and no complete public reverse-engineering report corroborates them, so parameters should be measured on real samples. Whatever the specifics, without the operators' private key there is nothing to reverse.

Block-based encryption is the decisive trait. NightSpire uses a speed-first hybrid strategy: large files such as iso, vhdx, vmdk, zip, bak and mdf are only partially encrypted block by block, while everything else is encrypted in full. No authoritative public figure for the block stride exists, so it has to be measured per sample. That distinction still drives the recovery plan. Virtual disks, database files and backup archives often retain large untouched regions that structural repair can exploit; Office documents, drawings and source files are typically overwritten completely and depend entirely on copies or backups.

Shadow copies. Unlike most mainstream families, public incident analysis does not record NightSpire systematically deleting volume shadow copies or disabling Windows recovery - Huntress notes the operators leaned on installed third-party tools rather than the native commands other crews use for this. That is no assurance copies survive in any given case: operators may still clear them by hand, and snapshots can be aged out by writes. But checking VSS immediately is essential, because it is an unusually valuable recovery window for this family. Treat it as a working assumption to verify on site, not as a property of the family.

Double extortion. Data is stolen before encryption; refusal leads to public naming on the leak site and staged publication of the data. Both 360 and ransomware.live record the pressure model as very short deadlines - as little as two days - combined with reputational exposure through public listing.

Assess before you act

Recoverability assessment

There is no shortcut with NightSpire. Feasibility has to be assessed sample by sample and file type by file type. We do not pay ransoms and do not negotiate on a client's behalf; our work is technical recovery and forensics.

1) Public decryptor: none exists. Neither No More Ransom nor any vendor has released a .nspire tool, and no exploitable key weakness has been disclosed. Any tool claiming direct decryption must be validated on copies first and never run against original disks.

2) Shadow copies and snapshots - the highest priority for this family. Because public incidents do not show systematic shadow-copy deletion (an observational finding that still has to be confirmed on site), VSS snapshots, storage-layer snapshots on NAS/SAN, hypervisor snapshots and untouched copies on the backup server frequently deliver the best recovery ratio. Inventory them within the first hour and avoid any writes that could age snapshots out.

3) Repair space left by block-based encryption of large files. Because iso, vhdx, vmdk, bak and mdf files are only partially encrypted block by block - with the stride measured per sample rather than assumed - virtual disks can often be repaired at the partition and filesystem level and mounted so inner files are extracted, while SQL Server, Oracle and MySQL data files may allow page-level extraction and logical rebuilds. Yield depends on whether critical structures - headers, page directories, log regions - happened to fall inside an encrypted block, so sample testing precedes any commitment.

4) Unencrypted copies and log replay. File-server recycle bins, endpoint caches, BI and reporting staging databases, ERP archive exports, database transaction logs and application audit logs can support reconstruction or point-in-time replay. Check OneDrive and cloud drives separately - encrypted cloud files keep their original extensions, so restoration must go folder by folder through version history and the recycle bin rather than assuming an unchanged extension means an untouched file.

5) Low-level carving. Where the encryptor wrote a new file and deleted the original, source data may remain in unallocated clusters and can be recovered through raw sector scanning, provided writes to the affected volumes stopped immediately.

We commit to a verifiable assessment and a clearly bounded recovery scope. We do not claim full decryption, and no technique can assure complete restoration of the data.

Our response plan

Hit by NightSpire ransomware? What to do

  1. Containment and forensic preservation

    Cut affected hosts off from production networks and storage paths, and do not reboot or power off. NightSpire installs Chrome Remote Desktop and AnyDesk as resident channels, so a reboot destroys memory evidence without removing persistence. Image or snapshot the domain controller, backup server, hypervisor management hosts and the Fortinet edge appliance first, export VPN, firewall and Active Directory logs, and keep three to five .nspire files plus the original ransom note. Freeze OneDrive sync clients immediately so cloud versions are not overwritten further.

  2. Family identification and encryption analysis

    Confirm the family from the .nspire extension, the structure of the readme.txt / _nightspire_readme.txt / [nspire_msg].txt note and file trailer markers, bearing in mind the encryptor is rebuilt per operation so hashes are not reusable. Two measurements matter most: the block stride and overwritten regions in large files, and a full inventory of affected files inside OneDrive sync folders that kept their original extensions. Together they decide whether the path is structural repair or version rollback.

  3. Recoverability and exposure assessment

    Start by inventorying shadow copies, storage and hypervisor snapshots, offline backups and cloud version history - the highest-return step in a NightSpire case. Then run sample repairs against core databases and virtual disks to estimate achievable recovery ratios. In parallel, size the exfiltration: reconstruct what left and how much from 7-Zip staging artefacts, MEGAsync/WinSCP/Rclone activity and egress logs, which drives regulatory notification duties and the response posture once the victim is named on the leak site. Execute only after a written assessment is signed off.

  4. Recovery execution and verification

    All work happens on images or copies with originals kept read-only. Restore in business priority order: identity and domain controllers first, then core databases such as ERP and MES, then file and mail systems, then endpoints. In virtualised environments, repair and mount virtual disks to extract data rather than overwriting the original datastores; roll OneDrive and cloud drives back folder by folder through version history. After each batch, run integrity checks and business-side verification - reconciliation, report comparison, application start-up tests - recorded in a traceable recovery manifest.

  5. Attribution, hardening and handover

    Reconstruct the full kill chain: whether the Fortinet appliance was still exposed to CVE-2024-55591, whether RDP faced the internet directly, which account's credentials were stolen, and when exfiltration occurred. Remove remote-access persistence such as Chrome Remote Desktop and AnyDesk along with rogue accounts and scheduled tasks; reset credentials domain-wide and enforce MFA on VPN and RDP; patch edge devices and close internet-facing management interfaces; rebuild backups to a 3-2-1 design with immutable copies; and extend version retention on OneDrive and other cloud drives. Close with an incident report and a formal handover checklist.

Risk warning

What not to do

  • Do not reboot or power off affected hosts. Losing memory-resident processes, key material and remote-access sessions destroys both forensic leads and partial recovery options - and persistence such as AnyDesk or Chrome Remote Desktop survives a reboot anyway.
  • Do not let OneDrive or other cloud drives keep syncing. Encrypted cloud files keep their original extensions, so the sync client will push encrypted content upstream and age out usable version history. Pause sync first, then roll back.
  • Do not run a downloaded "NightSpire decryptor" against original disks. No free decryptor exists for this family, unknown tools can cause further damage, and any validation must happen on copies.
  • Do not delete the readme.txt notes or the .nspire samples, and do not rush into a clean-up sweep. They are the only basis for build identification, block-stride measurement and a realistic recovery assessment.
  • Do not format, reinstall, rebuild RAID or storage pools, or reinitialise datastores. Doing so eliminates shadow copies and any chance of low-level carving.
  • Do not contact the mailbox or qTox ID in the note under the pressure of a 48-hour countdown. Payment does not reliably produce a working key, and it does not stop publication on the leak site.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related industries

Similar families

FAQ

NightSpire Frequently asked questions

  • Can .nspire files be decrypted?

    No free public decryptor exists for .nspire, and without the operators' private key there is no generic decryption algorithm. But "cannot be decrypted" is not the same as "cannot be recovered".

    The three highest-value routes in a NightSpire case are shadow copies and snapshots at every layer (this family is not recorded as systematically deleting VSS), the untouched regions left by block-based encryption of large files (virtual disks, database files and backup archives are candidates for structural repair), and version history in OneDrive and similar cloud drives. How much is actually recoverable has to be measured on samples rather than inferred from the extension.

  • OneDrive files kept their extensions - does that mean they are safe?

    No. This is the single most common misjudgement with NightSpire: files inside synced OneDrive folders are encrypted without any change to extension or icon, and the ransom note calls this out deliberately. Explorer looks normal, but the file opens as garbage.

    Two actions are urgent. First, pause the OneDrive sync client so encrypted content is not pushed upstream, ageing out usable versions. Second, work folder by folder through OneDrive version history and the recycle bin to restore clean versions. Scoping the incident by counting .nspire files alone will significantly understate the damage.

  • The note gives only 48 hours - should we pay to buy time?

    Very short deadlines are a standing NightSpire pressure tactic - both 360 and ransomware.live record demands for payment within about two days, backed by public naming on the leak site for reputational damage. These are negotiation levers, not technical deadlines: the files are already encrypted, and the countdown reaching zero changes nothing about their state.

    We do not pay ransoms and do not negotiate on a client's behalf. Payment does not reliably produce a working or complete decryptor, does not stop stolen data from being published or resold, and carries its own compliance and legal exposure. The better use of those 48 hours is containment, forensic preservation, a snapshot inventory and an exfiltration assessment - work that puts the initiative back on your side.

  • How did they get in, and where should we look first?

    Public analysis points to three places to check first. One: whether the Fortinet FortiOS/FortiProxy edge device still carries the unpatched CVE-2024-55591 authentication bypass, identified as the primary vector by both 360 and Barracuda. Two: RDP exposed directly to the internet or protected by weak credentials. Three: signs of phishing, MFA fatigue attacks, or abuse of a remote monitoring and management platform.

    Then sweep hosts for Chrome Remote Desktop and AnyDesk installations, and for the presence and execution of tools like Everything, 7-Zip, MEGAsync and WinSCP - the first of these are directly documented in published incident analysis, and comparable exfiltration utilities such as Rclone are worth folding into the same sweep. They map to the persistence, discovery and exfiltration phases respectively and anchor the incident timeline.

  • Our company is already listed on the NightSpire leak site - what now?

    Being named means the data is already in their hands, so recovery and exposure handling have to run in parallel.

    On the technical side, reconstruct which directories left, how much, and in what time window from 7-Zip staging artefacts, MEGAsync/WinSCP/Rclone execution records and egress traffic logs, producing an evidenced exfiltration inventory. On the management side, use that inventory to determine notification obligations under personal information and data security rules, prepare consistent messaging for customers, partners and regulators, and rotate every affected credential, API key and certificate - leaked credentials are routinely reused for follow-on intrusions or resold.

  • Does NightSpire's move to RaaS change what we should defend?

    What changes is the variety of tradecraft; the entry points stay the same. The group began recruiting affiliates publicly in April 2026, which means different affiliates bring their own intrusion habits and that static indicators - especially encryptor hashes, which are already rebuilt per operation - become progressively less reliable.

    Defence should therefore shift from signature matching toward exposure reduction plus behavioural detection: disciplined patching and version control on edge appliances, no internet-facing RDP and enforced MFA, alerting on unexpected installs of AnyDesk or Chrome Remote Desktop, monitoring for MEGAsync, Rclone and WinSCP alongside unusual egress volume, and backups that include offline or immutable copies.