Ransomware note
From extortion.wiki, the ransomware notes archive
- Family
- Nightspire
- Original file
- nightspire_readme.txt
- Source snapshot
- 2bbf5b4ecda8
- Archive ID
- note-nightspire-nightspire-readme-txt
A byte-attributed static rendering of the archived source text. Content is escaped, selectable, and inert; extortion.wiki does not execute markup, activate source URLs, submit forms, or load external resources from this document.
Archived note body
Plain text · original whitespace retained
-Your sensetive data are stolen and encrypted!
If you pay within 3 days, we will decrypt it and also, we will not public your data.
After that we will public this situation and all data.
-DO NOT MODIFY FILES YOURSELF.
-DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
-YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.
-YOUR DATA IS STRONGLY ENCRYPTED, YOU CAN NOT DECRYPT IT WITHOUT OUR HELP.
CONTACT US:
Onion Mail : nightspireteam.receiver@onionmail.org
qTox ID: 3B61CFD6E12D789A439816E1DE08CFDA58D76EB0B26585AA34CDA617C41D5943CDD15DB0B7E6
http://a2lyiiaq4n74tlgz4fk3ft4akolapfrzk772dk24iq32cznjsmzpanqd.onion
http://nspiremkiq44zcxjbgvab4mdedyh2pzj5kzbmvftcugq3mczx3dqogid.onion
Send this message first "NSPIRE[snip]" when contact with us, so to make sure it's you.
Related negotiation records
View all 7 recordsAn explicit alias maps the note family Nightspire to the Ransomchats actor label Nightspire. This relationship does not merge either corpus or its statistics.
| Record ID | Indexed date | Messages | Threat actor |
|---|---|---|---|
| 20260225 | Feb 25, 2026 | 48 | Nightspire |
| 20260217 | Feb 17, 2026 | 31 | Nightspire |
| 20260203 | Feb 03, 2026 | 45 | Nightspire |
| 20260127 | Jan 27, 2026 | 62 | Nightspire |
| 20251218 | Dec 18, 2025 | 84 | Nightspire |
| 20250428 | Apr 28, 2025 | 59 | Nightspire |
| 20250418 | Apr 18, 2025 | 38 | Nightspire |