NightSpire is a ransomware operation tracked by IntelFusions under the alias Spectral Flux. First observed in February 2025 and operating a Tor-based data leak site (DLS) since March 12, 2025, the group has claimed over 150 victims across 33 countries within its first year of operation. NightSpire functions as a closed, non-RaaS group executing all stages of the attack chain in-house, from initial access through extortion. The group is assessed with medium-high confidence as a rebrand of the Rbfs ransomware operation, based on overlapping victims, shared infrastructure indicators, and the concurrent cessation of Rbfs activity at the time of NightSpire's emergence. Sources for this profile include reporting by Halcyon, Cyble, SOCRadar, Broadcom, Ransom-DB, Xcitium ThreatLabs, HivePro, and Proven Data.
Origin and Organizational Structure
NightSpire's operational timeline begins in February 2025, with DLS activity commencing March 12, 2025 and continuing through at least December 30, 2025 per Ransom-DB tracking. The group presents as a closed operation, meaning attack execution is not distributed through an affiliate recruitment model in the conventional RaaS sense. However, on March 14, 2025, a BreachForums post attributed to the handle xdragon128, linked to the actors Paranodeus, CyberVolk, and DarkAssault, solicited a "negotiation specialist" at a 20% revenue split. This suggests at least partial outsourcing of victim negotiation, though a full affiliate structure has not been confirmed at scale. The ransomware payload is written in Go (Golang) and currently targets Windows environments. Expansion to Linux and ESXi is assessed as likely based on Go's cross-compilation capability and sector targeting patterns, but has not been confirmed in the wild as of this writing.
Initial Access and Attack Chain
NightSpire's primary documented initial access vector is CVE-2024-55591, a critical authentication bypass in FortiOS and FortiProxy affecting the Node.js WebSocket management interface. The vulnerability enables unauthenticated super-admin access and was disclosed by Fortinet on January 14, 2025, with exploitation observed in the wild from November 2024. NightSpire's early campaign timing aligns closely with the public disclosure window, consistent with opportunistic exploitation of newly published Fortinet vulnerabilities against organizations that had not yet patched. Secondary initial access methods include RDP brute-force and credential stuffing, phishing using browser and security update lures, VPN appliance exploitation, MFA fatigue attacks, and abuse of RMM platforms via compromised managed service providers.
Post-access execution relies on PowerShell, PsExec, and WMI for lateral movement, with AnyDesk deployed for persistent remote access. Persistence is established through scheduled tasks and registry run keys. Credential harvesting employs Mimikatz for LSASS memory dumping, with NTLM hash and Kerberos ticket extraction targeting domain controllers to achieve full Active Directory compromise. Network-wide file and directory enumeration is performed using Everything.exe.
Exfiltration is staged using 7-Zip and transferred via WinSCP, MEGACmd, or Rclone to attacker-controlled infrastructure. A notable technique is the encryption of OneDrive-synced files without extension modification, which suppresses cloud-side change detection signals and complicates victim recovery timelines. NightSpire does not delete Volume Shadow Copies, a deliberate trade-off in favor of encryption speed over post-encryption recovery prevention.
The encryption implementation uses hybrid AES (unique per-file symmetric key) wrapped with RSA-2048, with RC4/XOR obfuscation applied to the payload. Block encryption is applied to large file types (.iso, .vhdx, .vmdk, .bak), while all other files receive full encryption.
Victimology and Scale
As of early 2026, NightSpire has claimed over 150 victims across 33 countries, with Ransom-DB independently confirming 145 postings as of January 2026. The United States accounts for over 40% of victims. Secondary geographic concentration spans India, Hong Kong, Taiwan, Japan, France, Spain, Poland, and Egypt. Ransom demands range from $150,000 to $2 million.
Targeting is focused on SMEs with limited security infrastructure: organizations without dedicated security teams, inconsistent patch cycles, and lower MFA adoption. The top targeted sector is Manufacturing, accounting for more than one third of confirmed victims. Secondary sectors include Technology and IT Services, Financial Services, Healthcare, Business Services, Construction, Education, and Logistics. Confirmed named victims from public DLS postings include Hydro-Vacuum S.A. (Poland, manufacturing), Far East Consortium International Limited (Hong Kong, real estate), Baily International (Atlanta, US, financial and consulting), Business Ledger Limited (UK, financial services), healthcare institutions in the UAE, Taiwan, and Peru, and government entities in South Africa and Taiwan.
Q4 2025 represented a significant acceleration in activity. Ransom-DB recorded 15 DLS postings in November and December alone, including days with three to four simultaneous victim listings, indicating either expanded access operations or a stockpile release strategy.
Infrastructure and Communications
NightSpire operates two Tor-based DLS addresses:
- Primary:
nspireyzmvapgiwgtuoznlafqvlyz7ey6himtgn5bdvdcowfyto3yryd.onion - Secondary:
a2lyiiaq4n74tlgz4fk3ft4akolapfrzk772dk24iq32cznjsmzpanqd.onion
A C2 IP of 14.139.185.60 has been associated with WinSCP remote server operations. Victim communications use ProtonMail, OnionMail, Telegram, qTox, and custom Tor chat portals. The DLS features countdown timers (sometimes set to 48-hour deadlines), structured victim listings with breach dates and data volumes, and free download releases for non-paying victims.
Two OPSEC weaknesses stand out relative to the group's operational scale. First, a Gmail address (nightspireteam.receiver@gmail.com) has been used in victim communications, representing an unusual exposure for a group operating Tor infrastructure. Second, the DLS exposes Apache, OpenSSL, and PHP version fingerprints, enabling passive infrastructure profiling by researchers and defenders. These weaknesses are consistent with a group that has scaled quickly without proportionally maturing its operational security posture.
Assessment
NightSpire represents a fast-scaling ransomware threat with a clear SME targeting strategy and demonstrated capability to exploit enterprise-grade perimeter vulnerabilities within short windows of public disclosure. The Rbfs rebrand assessment, if accurate, indicates an experienced operator rather than a newly formed group, which aligns with the operational tempo and technical capability observed in the first year of NightSpire activity. The Go-based payload, hybrid encryption scheme, and OneDrive silent encryption technique suggest deliberate engineering choices rather than commodity tooling reuse. The Q4 2025 activity surge and multi-victim posting days indicate a group operating near or above its current negotiation and infrastructure management capacity, which may explain the BreachForums recruitment post for negotiation support. Organizations in the manufacturing, financial services, and healthcare sectors operating FortiOS or FortiProxy infrastructure without CVE-2024-55591 remediation applied should treat NightSpire as an active and credible threat.
This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. Claims described herein have not been independently verified unless explicitly stated.