logo

Nightspire CTI Report

ID: 5854201f-5b0a-464d-9dad-ddd46b363901

STIX ID: report--5854201f-5b0a-464d-9dad-ddd46b363901

Threat Score

75/100

Uploaded: 2026-06-10

Created by: dogesec

TLP:CLEAR
...
...
NightSpire is a Go 1.24.11–compiled ransomware family that enumerates Windows volumes, spawns parallel goroutines (one per drive), and performs intermittent AES-256-CTR file encryption with per-file keys wrapped by an embedded RSA-4096 public key; the sample includes plaintext infrastructure strings (onion URLs, emails), a file-tail signature ("sNightspire"), and numerous IOCs and hunting queries to detect pre-encryption volume enumeration and mass .nspire file creation.