Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors nightsky

Description

Night Sky is a China-nexus ransomware group (attributed to the "Emperor Dragonfly" cluster) that emerged in late 2021, gaining notoriety in early 2022 by exploiting the Log4Shell vulnerability (CVE-2021-44228) to target corporate networks across healthcare, finance, government, and manufacturing using multi-extortion tactics. Known victims: 2

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Night Sky is a medium-sophistication cybercriminal threat actor with a primary motivation of organizational disruption and financial gain through ransomware activity. Emerging in early 2022, the group gained notoriety by exploiting the Log4Shell vulnerability (CVE-2021-44228) to target corporate networks across healthcare, finance, government, and manufacturing sectors using multi-extortion tactics.

Goals & Targeting

Night Sky targets industries where ransom payments are likely to be high and data breaches would cause significant reputational damage. The group's selection of healthcare, finance, government, and manufacturing sectors reflects a strategic focus on entities with both financial resources and sensitive data. Night Sky operates globally, exploiting vulnerabilities in widely used software to gain initial access to victim networks. This broad targeting approach suggests an intention to maximize the geographic and sectoral impact of its campaigns.

Enhanced Description

Night Sky is a ransomware group attributed to the 'Emperor Dragonfly' cluster and based in China. The group emerged in late 2021 and gained prominence in early 2022 by leveraging the Log4Shell vulnerability to compromise corporate networks. Known for targeting critical infrastructure sectors, Night Sky employs multi-extortion tactics that combine ransomware encryption with data exfiltration and leak threats to pressure victims into paying ransoms. The group's activities have been linked to high-profile incidents involving healthcare providers, financial institutions, and government entities, indicating a focus on sectors with significant data value or operational disruption potential.

Key Capabilities

  • Exploitation of Log4Shell vulnerability (CVE-2021-44228)
  • Multi-extortion tactics combining ransomware encryption with data exfiltration
  • Ransomware deployment using Phobos ransomware family
  • Lateral movement within networks using RDP protocols
  • Data collection and exfiltration techniques
  • Brute-force attacks on network resources
  • Credential dumping operations

MITRE ATT&CK Tactics

Initial Access
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1203.001 - Exploit Publicly disclosed vulnerability in software
T1567.002 - Encrypt data for impact
T1567.003 - Leak data to cause chaos or fear
T1098 - Use of credentials brute force
T1077 - Validate account using legitimate credentials via remote desktop protocol
T1534.002 - Exfiltration over alternative protocols
T1531 - OS Credential Dumping
T1485 - Delete system files/directories
T1053 - Scheduled Task Injection

Software / Tooling

Phobos Ransomware Family
custom data exfiltration tools
remote desktop protocol (RDP) brute-force utilities
credential-dumping tools like mimikatz alternative

Campaigns & Victims

Night Sky's campaigns demonstrate a focus on high-value targets with significant operational disruption potential. The group's exploitation of Log4Shell highlights its ability to quickly adopt and leverage zero-day vulnerabilities for large-scale attacks. Multi-extortion tactics, including data encryption and exfiltration, are used to maximize financial gains and coerce victims into paying ransoms. Campaigns have been observed targeting organizations in North America, Europe, and Asia, with a particular emphasis on healthcare and finance sectors. Notable operations include the compromise of multiple healthcare providers and financial institutions in early 2022.

IOC Patterns

  • Exploitation of Log4Shell vulnerability (CVE-2021-44228)
  • RDP brute-force attempts targeting network endpoints
  • Network traffic associated with known Phobos ransomware activity patterns
  • Spear-phishing emails (though none were specified in the data)
  • Encrypted communication channels for extortion negotiations

Recommended Actions

  • Patch and remediate Log4j vulnerabilities across all environments
  • Monitor network logs for signs of RDP brute-force attempts
  • Enhance RDP security by implementing multi-factor authentication
  • Implement endpoint detection and response (EDR) solutions to detect ransomware activity
  • Conduct regular backups of critical systems and isolate backup resources
  • Educate employees on phishing and social engineering attacks
  • Establish incident response plans for potential ransomware incidents

Suggested Tags

Criminal
Ransomware
Financial Gain
Multi-Extortion
Healthcare Sector Targeting
Finance Sector Targeting
Government Sector Targeting
Manufacturing Sector Targeting

Confidence Assessment

Confidence in the data is high given the reputable sources and clear indicators of Night Sky's activity. However, there are gaps in understanding the full scope of their operations, including their geographic reach beyond known campaigns and the extent of their affiliations within the 'Emperor Dragonfly' cluster.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Government Targeting
Criminal
Financial Gain
Multi-Extortion
Healthcare Sector Targeting
Finance Sector Targeting
Government Sector Targeting
Manufacturing Sector Targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jan 4, 2022
Last Seen
Jan 4, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.