Huntress analysts investigated two NightSpire ransomware incidents (December 2025 and March 2026) and found meaningful differences in TTPs and tooling between them, raising questions about whether NightSpire operates as a RaaS with affiliates. The March 2026 attack used Chrome Remote Desktop, AnyDesk, MEGASync, 7Zip, Everything, VMware Workstation, and WPS Office — none native to the victim environment — contrasting with publicly reported NightSpire attacks that leveraged LOLBins like WMI and PsExec. The ransom note filenames and encryptor hashes also changed between incidents. The key takeaway for defenders: IOCs tied to ransomware groups are not static, especially when affiliates may be involved, and relying on a fixed set of indicators can lead to missed detections or incomplete scoping during incident response.