Night Sky

Malware updated 2 months ago (2024-07-22T15:18:11.014Z)
Download STIX
Preview STIX
Night Sky is a potent form of malware that has been linked to several significant ransomware activities, including LockFile, AtomSilo, Rook, and Pandora. Analysis of the Cobalt Strike Beacon samples loaded by HUI Loader has revealed a connection between AtomSilo, Night Sky, and Pandora ransomware, suggesting similarities across these ransomware families. Further research indicates that the five ransomware families connected to HUI Loader were developed from two distinct codebases: one for LockFile and AtomSilo, and the other for Rook, Night Sky, and Pandora. This suggests a level of coordination and shared resources among these malicious actors. The operational patterns and victimology of LockFile, AtomSilo, Rook, Night Sky, and Pandora deployments do not align with conventional financially motivated cybercrime operations, indicating a more complex motivation or strategy behind these attacks. As of mid-April, 21 victims have been listed across the AtomSilo, Rook, Night Sky, and Pandora leak sites, demonstrating the widespread impact of these threats. The deployment of LockFile, AtomSilo, Rook, Night Sky, and Pandora post-intrusion ransomware further underscores the significant threat posed by these malware families. Additional analysis has uncovered a link between Night Sky and Emperor Dragonfly, a Chinese ransomware group. A reference to a Chinese font family in a Night Sky ransom note, along with the detection of a Chinese character font in another ransom note dropped by Night Sky ransomware, points towards a possible origin or affiliation. These findings highlight the global nature of the cyber threat landscape and underscore the need for robust cybersecurity measures to counter such sophisticated threats.
Description last updated: 2024-07-22T15:16:38.505Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Night Sky Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Unit42
2 months ago
From RA Group to RA World: Evolution of a Ransomware Group
CERT-EU
8 months ago
A Murder at the End of the World Makes Hacker Style Freaky Again | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
8 months ago
Serbian Police’s Expanding Drone Arsenal Draws Concern – Analysis
CERT-EU
a year ago
NIST 800-82 R2/R3: A Practical Guide for OT Security Professionals
CERT-EU
a year ago
Hashtag Trending Aug.1- Will AI hit higher paying jobs first?; FraudGPT, the newest tool for cybercriminals; Twitter removes brightly lit X logo placed on its headquarters | IT World Canada News
CERT-EU
a year ago
Hackaday Podcast 226: Ice, Snow, And Cooling Paint In July
Secureworks
2 years ago
BRONZE STARLIGHT Ransomware Operations Use HUI Loader