NightSpire — Ransomware Profile

NightSpire is a financially motivated ransomware group that emerged in early 2025, operating as a likely rebrand of the Rbfs ransomware operation, with overlapping victims, shared infrastructure, and coincident cessation of Rbfs activity. The group employs double extortion (encrypting systems while exfiltrating data and threatening publication on a Tor-based leak site active since March 12, 2025) and operates as a closed, non-RaaS syndicate handling all intrusions in-house. Primary initial access vector is CVE-2024-55591, a critical FortiOS/FortiProxy authentication bypass enabling super-admin privilege escalation without valid credentials. NightSpire relies exclusively on living-off-the-land tooling (MEGACmd, WinSCP, 7-Zip, PowerShell, PsExec, WMI) with ransomware written in Golang; by late 2025 the group had claimed over 145 victims across 33 countries, with US organizations accounting for over 40% of targets and manufacturing the most heavily affected sector.

Also tracked as

Rbfs

IntelFusions coverage (7)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions