NightSpire Ransomware Exploits RDP, Remote Admin Tools for Stealthy Persistence
Key Takeaways NightSpire, a recently discovered ransomware, is actively targeting a broad spectrum of organizations globally since early 2025. The ransomware utilizes Remote Desktop Protocol (RDP)...
Key Takeaways
- NightSpire, a recently discovered ransomware, is actively targeting a broad spectrum of organizations globally since early 2025.
- The ransomware utilizes Remote Desktop Protocol (RDP) and legitimate remote administration tools like Chrome Remote Desktop and AnyDesk for initial access and stealthy persistence.
- NightSpire employs a double extortion model, first exfiltrating sensitive data, then encrypting systems, and threatening to publish stolen information on a Tor-based leak site if ransom is not paid.
- The attacks have impacted at least 64 organizations across 33 countries between March and June 2025, spanning diverse sectors including healthcare, education, government, finance, manufacturing, hospitality, IT, and logistics.
- The ransomware encrypts files, appending the .nspire extension, and uniquely encrypts OneDrive files without altering their extensions, making detection challenging.
NightSpire Ransomware: A Stealthy Threat Leveraging Trusted Tools
A new ransomware variant, dubbed NightSpire, has emerged as a significant threat, actively compromising organizations across various sectors and geographies. First observed in early 2025, NightSpire distinguishes itself through a methodical, low-profile attack chain that heavily relies on standard IT administration tools to evade detection and maintain persistence.
Table Of Content
Researchers at Picus Security have conducted a detailed analysis of NightSpire’s tactics, techniques, and procedures (TTPs), highlighting its preference for Remote Desktop Protocol (RDP) for initial infiltration. This allows the ransomware operators to blend seamlessly into network traffic, making their presence difficult for traditional security systems to flag.
Double Extortion Model and Global Reach
NightSpire employs a robust double extortion strategy. Attackers first exfiltrate sensitive data from compromised networks before proceeding to encrypt the victim’s systems. Should the victim refuse to meet their demands, the threat actors leverage a Tor-based leak website to publish the stolen information.
The ransomware’s reach is extensive. Between March and June 2025 alone, NightSpire successfully attacked at least 64 organizations across 33 countries. The United States accounts for the highest number of victims, followed by Turkey, Hong Kong, Japan, Taiwan, Mexico, Spain, and Egypt. The targeted industries are diverse, encompassing healthcare, education, government, financial institutions, manufacturing, hospitality, IT services, and logistics, indicating a broad and opportunistic targeting strategy.
Go-Based Encryptor and Evasion Techniques
The NightSpire encryptor is developed in Go, a programming language favored for its ability to create lightweight, cross-platform executables. Encrypted files are marked with the .nspire extension, and a ransom note is placed in each affected directory. A particularly insidious feature noted by Picus Security is the ransomware’s capacity to encrypt OneDrive files without changing their extensions, a tactic designed to catch victims unaware and delay discovery.
Picus Security emphasized in their report that a key concern for defenders is NightSpire’s deliberate use of legitimate software. This approach allows the ransomware to mimic normal network activity, enabling attackers to remain undetected within a network for extended periods. “What makes NightSpire especially concerning for defenders is its deliberate use of trusted software to blend into normal network activity and avoid detection for as long as possible,” Picus Security stated.
Initial Access and Persistent Foothold
NightSpire’s initial access typically begins with the exploitation of Remote Desktop Protocol (RDP). Once inside a victim’s network, rather than deploying custom malware that might trigger alerts, the attackers install commercially available and widely trusted remote administration software to establish a persistent foothold.
Examples of this behavior include the deployment of Chrome Remote Desktop on at least two compromised machines. This tool was installed as a persistent Windows service named “Chrome Remote Desktop Service,” linked to the Google account prince1990905@gmail[.]com. On another endpoint, AnyDesk was installed, configured to launch automatically on system reboot via a Windows service and a startup shortcut. This tactic allows the attackers to maintain long-term access with minimal effort and a reduced risk of detection.
Discovery, Exfiltration, and Encryption at Scale
Once persistence is established, the NightSpire operators quickly move to identify and gather valuable data. They leverage legitimate utilities such as “Everything” by voidtools, a fast file search application, to rapidly locate sensitive documents across all drives. Identified data is then compressed into password-protected 7-Zip archives, streamlining the exfiltration process.
These archives are subsequently uploaded to MEGA cloud storage using MEGAsync, a legitimate synchronization tool. This further aids in evading detection, as cloud storage synchronization traffic is often deemed normal network activity. Following data exfiltration, the Go-based encryptor is executed, traversing all accessible drives and paths, renaming files with the .nspire extension, and distributing ransom notes throughout the affected system.
What You Should Do
- Restrict RDP Access: Limit RDP access to only necessary personnel and IP addresses. Implement strong, unique passwords and multi-factor authentication (MFA) for all RDP connections.
- Monitor Remote Access Tools: Continuously monitor for unexpected installations or usage of remote administration tools (e.g., Chrome Remote Desktop, AnyDesk) and cloud synchronization applications (e.g., MEGAsync).
- Enforce Application Whitelisting: Implement application whitelisting to prevent the execution of unauthorized software, including legitimate tools that could be abused by attackers.
- Regular Backups: Maintain frequent, offline, and immutable backups of critical data to ensure recovery in case of encryption.
- Network Segmentation: Segment your network to limit the lateral movement of attackers and contain potential ransomware outbreaks.
- Employee Training: Educate employees on identifying phishing attempts and practicing good cybersecurity hygiene, as initial RDP compromise often stems from compromised credentials.
- Simulate Attacks: Conduct regular penetration testing and red team exercises, specifically simulating NightSpire’s TTPs, to identify and address weaknesses in your defenses.
Indicators of Compromise (IoCs):



No Comment! Be the first one.