Skip to content
NightSpire Ransomware Abuses RDP for Stealthy Persistence

NightSpire Ransomware Abuses RDP for Stealthy Persistence

Gbhackers May 26, 2026

NightSpire has quickly emerged as a significant ransomware threat since its discovery in early 2025, combining classic double-extortion tactics with stealthy intrusion techniques. The malware not only encrypts victim data but also exfiltrates sensitive files, threatening to publish them on a Tor-based leak site if ransom demands are not met.

In just a three-month window between March and June 2025, NightSpire operators compromised at least 64 organizations across 33 countries, with the United States reporting the highest number of victims, followed by Turkey, Hong Kong, Japan, Taiwan, Mexico, Spain, and Egypt.

The ransomware has impacted a wide range of sectors, including healthcare, government, finance, manufacturing, and IT services, indicating a broad targeting strategy rather than a sector-specific campaign.

Its rapid spread and operational efficiency highlight a well-organized threat group leveraging legitimate tools to evade detection and maintain persistence within compromised environments.

Instead of deploying custom persistence mechanisms that could raise suspicion, attackers rely on legitimate remote administration tools such as Chrome Remote Desktop and AnyDesk. These tools allow them to blend into normal system activity while maintaining long-term access.

In observed intrusions, Chrome Remote Desktop was installed as a Windows service, enabling continuous remote control tied to attacker-controlled accounts.

Similarly, AnyDesk was configured with both a system service and startup persistence, ensuring access even after system reboots. This approach reduces the likelihood of detection because these tools are widely used in legitimate IT operations .

Once inside, attackers deploy additional trusted utilities to facilitate their operations. The “Everything” tool is used to rapidly index and locate valuable files across the system.

According to Picus , NightSpire attacks often begin with unauthorized access through Remote Desktop Protocol (RDP), a common entry point in enterprise environments.

Selected data is then compressed using 7-Zip, often with password protection to prevent inspection. Finally, the MEGAsync client is used to exfiltrate the archived data to MEGA cloud storage, completing the data theft phase before encryption begins.

The NightSpire encryptor is written in Go, a programming language increasingly favored by threat actors for its portability and ease of cross-platform compilation. This allows the same codebase to be adapted for Windows, Linux, and macOS environments with minimal changes, increasing the threat’s reach.

Upon execution, the ransomware scans all accessible directories and drives, systematically encrypting files and appending the “.nspire” extension. It also drops a ransom note in every affected folder.

Notably, NightSpire extends its impact beyond local storage by targeting files synced with OneDrive , effectively encrypting data before or during cloud synchronization.

The ransom message warns victims that both local and cloud-based files have been compromised, reinforcing the pressure to pay. This dual impact on on-premise and cloud data significantly increases operational disruption for targeted organizations.

Security teams are encouraged to proactively test their defenses against NightSpire using breach and attack simulation tools such as the Picus Security Validation Platform.

The Picus Threat Library includes specific scenarios like Threat ID 79926 for download-based attacks and 95001 for email-based delivery, enabling organizations to assess detection and response capabilities against realistic attack chains.

As NightSpire continues to evolve, its use of legitimate tools, combined with efficient data exfiltration and cross-platform encryption, makes it a serious and adaptable ransomware threat that defenders must actively prepare for.

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Multiple high-severity vulnerabilities have been discovered in the Angular Language Service VS Code extension (Angular.ng-template),…

China-linked hackers are conducting a stealthy infrastructure-centric espionage campaign across Southeast Asia by compromising Linux-based…

A newly identified vulnerability in Memcached has raised concerns among security professionals after researchers confirmed…

Hackers are actively exploiting a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) to compromise…

Apache CXF users are facing a significant security risk following the disclosure of a new…

Hackers are increasingly abusing engine optimization (SEO) techniques to distribute malware by impersonating popular…