Uptime Hamster: 10d 8h 9mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza nightsky

nightsky

2 incidentes 2 paises 2 sectores ransomware CN Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Nightsky is a financially motivated ransomware group that emerged in late December 2021, operating as a short-lived double-extortion ransomware variant. It is strongly linked to the China-based threat actor group known as BRONZE STARLIGHT, also tracked as DEV-0401 or Emperor Dragonfly, which is known for deploying multiple ransomware strains. Nightsky differentiates itself by being a derivative of the Rook ransomware, which itself is based on the leaked Babuk encryptor, often obfuscated with VMProtect. The group’s primary objective is financial gain through high ransom demands, and they are notable for their rapid exploitation of critical vulnerabilities like Log4Shell for initial network infiltration, combining data encryption with threats of public data leakage.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknowngg5ryfgogainisskdvh4y373ap3b2mxafcibeh2lvq5x7fx76ygcosad.onionnightsky
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: nightsky
Tecnicas MITRE
T1078.001, T1059, T1562.001
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

China (1) United States (1)

Paises objetivo (SOCRadar)

BangladeshJapanUnited States

Sectores atacados

Software (1) Healthcare (1)

Sectores objetivo (SOCRadar)

Food ManufacturingSoftware PublishersEnterprises & HoldingManufacturingElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationBeverag & Tobacco ManufacturingEducational ServicesTextile & Fabric ManufacturingEnergy & Utilities

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com