Huntress analysts investigated two NightSpire ransomware incidents (December 2025 and March 2026) and found meaningful differences in TTPs and tooling between them, raising questions about whether NightSpire operates as a RaaS with affiliates. The March 2026 attack used Chrome Remote Desktop, AnyDesk, MEGASync, 7Zip, Everything, VMware Workstation, and WPS Office — none native to the victim environment — contrasting with publicly reported NightSpire attacks that leveraged LOLBins like WMI and PsExec. The ransom note filenames and encryptor hashes also changed between incidents. The key takeaway for defenders: IOCs tied to ransomware groups are not static, especially when affiliates may be involved, and relying on a fixed set of indicators can lead to missed detections or incomplete scoping during incident response.

7m read timeFrom huntress.com
Post cover image
Table of contents
Is NightSpire RaaS?NightSpire incidentPrevious NightSpire incidentObservationsIndicators of Compromise