NightSpire — Ransomware Profile

NightSpire is a financially motivated ransomware group that emerged in early 2025, operating as a likely rebrand of the Rbfs ransomware operation, with overlapping victims, shared infrastructure, and coincident cessation of Rbfs activity. The group employs double extortion — encrypting systems while exfiltrating data and threatening publication on a Tor-based leak site active since March 12, 2025 — and operates as a closed, non-RaaS syndicate handling all intrusions in-house. Primary initial access vector is CVE-2024-55591, a critical FortiOS/FortiProxy authentication bypass enabling super-admin privilege escalation without valid credentials. NightSpire relies exclusively on living-off-the-land tooling (MEGACmd, WinSCP, 7-Zip, PowerShell, PsExec, WMI) with ransomware written in Golang; by late 2025 the group had claimed over 145 victims across 33 countries, with US organizations accounting for over 40% of targets and manufacturing the most heavily affected sector.

Also tracked as

Rbfs

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions