Night Sky is a China-nexus ransomware group (attributed to the "Emperor Dragonfly" cluster) that emerged in late 2021, gaining notoriety in early 2022 by exploiting the Log4Shell vulnerability (CVE-2021-44228) to target corporate networks across healthcare, finance, government, and manufacturing using multi-extortion tactics. Known victims: 2
Objectives
Executive Summary
Night Sky is a medium-sophistication cybercriminal threat actor with a primary motivation of organizational disruption and financial gain through ransomware activity. Emerging in early 2022, the group gained notoriety by exploiting the Log4Shell vulnerability (CVE-2021-44228) to target corporate networks across healthcare, finance, government, and manufacturing sectors using multi-extortion tactics.
Goals & Targeting
Night Sky targets industries where ransom payments are likely to be high and data breaches would cause significant reputational damage. The group's selection of healthcare, finance, government, and manufacturing sectors reflects a strategic focus on entities with both financial resources and sensitive data. Night Sky operates globally, exploiting vulnerabilities in widely used software to gain initial access to victim networks. This broad targeting approach suggests an intention to maximize the geographic and sectoral impact of its campaigns.
Enhanced Description
Night Sky is a ransomware group attributed to the 'Emperor Dragonfly' cluster and based in China. The group emerged in late 2021 and gained prominence in early 2022 by leveraging the Log4Shell vulnerability to compromise corporate networks. Known for targeting critical infrastructure sectors, Night Sky employs multi-extortion tactics that combine ransomware encryption with data exfiltration and leak threats to pressure victims into paying ransoms. The group's activities have been linked to high-profile incidents involving healthcare providers, financial institutions, and government entities, indicating a focus on sectors with significant data value or operational disruption potential.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Night Sky's campaigns demonstrate a focus on high-value targets with significant operational disruption potential. The group's exploitation of Log4Shell highlights its ability to quickly adopt and leverage zero-day vulnerabilities for large-scale attacks. Multi-extortion tactics, including data encryption and exfiltration, are used to maximize financial gains and coerce victims into paying ransoms. Campaigns have been observed targeting organizations in North America, Europe, and Asia, with a particular emphasis on healthcare and finance sectors. Notable operations include the compromise of multiple healthcare providers and financial institutions in early 2022.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is high given the reputable sources and clear indicators of Night Sky's activity. However, there are gaps in understanding the full scope of their operations, including their geographic reach beyond known campaigns and the extent of their affiliations within the 'Emperor Dragonfly' cluster.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics