nightsky

Ransomware
Origin🇨🇳 China
Sourceransomware.live

Vexday analysis

NightSky é uma operação de ransomware vinculada à China, atribuída ao cluster denominado "Emperor Dragonfly", que surgiu no final de 2021 e ganhou notoriedade no início de 2022 ao explorar a vulnerabilidade Log4Shell (CVE-2021-44228) para comprometer redes corporativas. O grupo adota táticas de múltipla extorsão e tem como alvos setores como saúde, finanças, governo e manufatura.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

nightsky uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →