Leveling Up with NightSpire Ransomware

NightSpire ransomware, first discovered in February 2025, presents a categorization challenge regarding whether it operates as Ransomware-as-a-Service (RaaS). Analysis of two incidents from December 2025 and March 2026 reveals significant variations in tactics, techniques, and procedures between attacks. The March 2026 incident involved threat actors installing Chrome Remoting Desktop and AnyDesk for persistence, using Everything and 7Zip for data staging, MEGASync for exfiltration, and deploying VMWare Workstation and WPS Office. The attacker accessed systems via RDP days before detection. Comparison with the December 2025 incident shows evolution in the ransomware encryptor, including modified ransom note filenames and contents. These variations in TTPs and indicators suggest either operational evolution or involvement of multiple affiliates, demonstrating that ransomware indicators aren't consistent across campaigns.

Pulse ID: 69d61cc749755c1135d6faa9
Pulse Link: https://otx.alienvault.com/pulse/69d61cc749755c1135d6faa9
Pulse Author: AlienVault
Created: 2026-04-08 09:15:51

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#7Zip #AnyDesk #Chrome #CyberSecurity #ICS #InfoSec #OTX #Office #OpenThreatExchange #RAT #RDP #RaaS #RansomWare #RansomwareAsAService #VMware #ZIP #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly

Protect your systems with RDP sticky keys backdoor detection. Learn essential detection methods and tips in our latest post.

Praetorian
Windows App : comment se connecter à un PC à distance (RDP)

Windows App permet désormais de se connecter à un PC à distance en RDP, même sans compte professionnel. Voici comment faire.

JustGeek

How can I make Windows 11 (24H2) RDP connect to Ubuntu 25.10 #rdp #windows11

https://askubuntu.com/q/1565357/612

How can I make Windows 11 (24H2) RDP connect to Ubuntu 25.10

I am trying to connect to my Ubuntu 25.10 running on a Dell XPS15 9550 using Windows 11 (24H2) RDP. I cannot make it work. I have spent many, many hours working both with Gemini and Claude, but ne...

Ask Ubuntu

4 Steps to Easily Access #RDP Remote Desktop with #Windows #VPS

Read this guide, "4 Steps to Easily Access RDP Remote Desktop with Windows VPS" to connect your Windows VPS to RDP (remote desktop protocol). RDP technology also fulfills other IT needs. For example, some computers, such as rack-mounted servers in data centers, don't have input ...
Continued 👉 https://blog.radwebhosting.com/access-rdp-remote-desktop-with-windows-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #windowsserver #vpsguide #microsoftremotedesktop #remotedesktopprotocol #rdpserver #vpsservers #vpsplatform

4 Steps to Easily Access #RDP Remote Desktop with #Windows #VPS

Read this guide, "4 Steps to Easily Access RDP Remote Desktop with Windows VPS" to connect your Windows VPS to RDP (remote desktop protocol). RDP technology also fulfills other IT needs. For example, some computers, such as rack-mounted servers in data centers, don't have input ...
Continued 👉 https://blog.radwebhosting.com/access-rdp-remote-desktop-with-windows-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #windowsserver #vpsplatform #remotedesktopprotocol #rdpserver #vpsguide #microsoftremotedesktop #vpsservers

4 Steps to Easily Access #RDP Remote Desktop with #Windows #VPS

Read this guide, "4 Steps to Easily Access RDP Remote Desktop with Windows VPS" to connect your Windows VPS to RDP (remote desktop protocol). RDP technology also fulfills other IT needs. For example, some computers, such as rack-mounted servers in data centers, don't have input ...
Continued 👉 https://blog.radwebhosting.com/access-rdp-remote-desktop-with-windows-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #vpsguide #vpsservers #rdpserver #remotedesktopprotocol #vpsplatform #microsoftremotedesktop #windowsserver

I have a lot of empathy for #GNOME users who struggle to figure out a way to do unattended graphical remote desktop to their own computers, as it silently refuses to work when the screen is locked or blanked.

There's an extension to work around that security limitation, but you have to know such a limitation exists to begin with.

Here I am suggesting an explanatory label in the GNOME Settings app to alleviate this for the foreseeable future: https://gitlab.gnome.org/GNOME/gnome-control-center/-/issues/3716

#UX #usability #RDP #design

Improve Desktop Sharing's explanation label to clarify that it won't work when screen is locked or display is blanked (#3716) · Issues · GNOME / Settings · GitLab

Problem statement In recent versions of GNOME, the UI for RDP in VNC-style remote assistance...

GitLab

@mort OK, same usecase as me. If you're comfortable with the security implication that your screen gets unlocked remotely (i.e.: host computer displays the contents on its local monitor), then this works well for me: https://extensions.gnome.org/extension/4338/allow-locked-remote-desktop/

This will allow you to remotely lift the lockscreen, and it also prevents display power management from entirely cutting off the connection.

It's a stopgap until "hybrid" sessions:
* https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/3212
* https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/91 etc.

#RDP #GNOME

Allow Locked Remote Desktop - GNOME Shell Extensions

curious what #developers are using for display on #Linux? I made the transition to #wayland from #x11 several years ago but the #remote access is still freaking frustrating.

I've used #Gnome #RDP, #RustDesk, and others.

#question #help