Uptime Hamster: 21d 3h 42mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza nightsky

nightsky

2 incidentes 2 paises 2 sectores threat-actor CN Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Nightsky is a financially motivated ransomware group that emerged in late December 2021, operating as a short-lived double-extortion ransomware variant. It is strongly linked to the China-based threat actor group known as BRONZE STARLIGHT, also tracked as DEV-0401 or Emperor Dragonfly, which is known for deploying multiple ransomware strains. Nightsky differentiates itself by being a derivative of the Rook ransomware, which itself is based on the leaked Babuk encryptor, often obfuscated with VMProtect. The group’s primary objective is financial gain through high ransom demands, and they are notable for their rapid exploitation of critical vulnerabilities like Log4Shell for initial network infiltration, combining data encryption with threats of public data leakage.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: nightsky
DLS / onionofflinegg5ryfgogainisskdvh4y373ap3b2mxafcibeh2lvq5x7fx76ygcosad.onionCTI.FYI
Tecnicas MITRE
T1078.001, T1059, T1562.001
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) China (1)

Paises objetivo (OSINT)

BangladeshJapanUnited States

Sectores atacados

Healthcare (1) Software (1)

Sectores objetivo (OSINT)

Food ManufacturingSoftware PublishersEnterprises & HoldingManufacturingElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationBeverag & Tobacco ManufacturingEducational ServicesTextile & Fabric ManufacturingEnergy & Utilities

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com