SYMBOLCOMMON_NAMEaka. SYNONYMS
win.nightsky (Back to overview)

NightSky

aka: Night Sky
VTCollection    

There is no description at this point.

References
2022-06-23 ⋅ Secureworks ⋅ Counter Threat Unit ResearchTeam
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
ATOMSILO Cobalt Strike HUI Loader LockFile NightSky Pandora PlugX Quasar RAT Rook SodaMaster BRONZE STARLIGHT
2022-05-09 ⋅ Microsoft ⋅ Microsoft 365 Defender Threat Intelligence Team, Microsoft Threat Intelligence Center (MSTIC)
Ransomware-as-a-service: Understanding the cybercrime gig economy and how to protect yourself
AnchorDNS BlackCat BlackMatter Conti DarkSide HelloKitty Hive LockBit REvil FAKEUPDATES Griffon ATOMSILO BazarBackdoor BlackCat BlackMatter Blister Cobalt Strike Conti DarkSide Emotet FiveHands Gozi HelloKitty Hive IcedID ISFB JSSLoader LockBit LockFile Maze NightSky Pandora Phobos Phoenix Locker PhotoLoader QakBot REvil Rook Ryuk SystemBC TrickBot WastedLocker BRONZE STARLIGHT
2022-02-01 ⋅ Youtube (OALabs) ⋅ OALabs
How To Unpack VMProtect 3 (x64) Night Sky Ransomware With VMPDump [Patreon Unlocked]
NightSky
2022-01-25 ⋅ Cynet ⋅ Orion Threat Research and Intelligence Team
Threats Looming Over the Horizon
Cobalt Strike Meterpreter NightSky
2022-01-11 ⋅ Twitter (@cglyer) ⋅ Christopher Glyer
Thread on DEV-0401, a china based ransomware operator exploiting VMware Horizon with log4shell and deploying NightSky ransomware
Cobalt Strike NightSky
2022-01-11 ⋅ Twitter (@cglyer) ⋅ Christopher Glyer
Tweet on CN based ransomware operator using log4shell to deploy NightSky
NightSky BRONZE STARLIGHT
2022-01-06 ⋅ BleepingComputer
Night Sky is the latest ransomware targeting corporate networks
NightSky
2021-12-11 ⋅ Microsoft ⋅ Microsoft 365 Defender Threat Intelligence Team, Microsoft Threat Intelligence Center (MSTIC)
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
Khonsari NightSky BRONZE STARLIGHT
Yara Rules
[TLP:WHITE] win_nightsky_auto (20260917 | Detects win.nightsky.)
rule win_nightsky_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.nightsky."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nightsky"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4885c0 74e2 c744242000000000 48634c2420 }
            // n = 4, score = 100
            //   4885c0               | inc                 ecx
            //   74e2                 | xor                 edi, dword ptr [esi + ecx*4 + 0x57110]
            //   c744242000000000     | inc                 ebp
            //   48634c2420           | mov                 ebx, ecx

        $sequence_1 = { f5 44310c24 f6c1e1 d2ff 5b 4185f7 }
            // n = 6, score = 100
            //   f5                   | rcr                 ecx, 0x41
            //   44310c24             | inc                 bp
            //   f6c1e1               | xchg                ecx, ecx
            //   d2ff                 | ret                 
            //   5b                   | dec                 eax
            //   4185f7               | inc                 ecx

        $sequence_2 = { 44894de4 418bd9 4533848d106d0500 473384b510690500 400fb6cf 448bce 4533848d107d0500 }
            // n = 7, score = 100
            //   44894de4             | and                 edx, edi
            //   418bd9               | movzx               edx, byte ptr [esi]
            //   4533848d106d0500     | inc                 esp
            //   473384b510690500     | movzx               edx, dx
            //   400fb6cf             | xor                 dl, bl
            //   448bce               | stc                 
            //   4533848d107d0500     | inc                 ecx

        $sequence_3 = { c60000 4885ff 7445 48837e2010 }
            // n = 4, score = 100
            //   c60000               | not                 dh
            //   4885ff               | inc                 eax
            //   7445                 | setl                dh
            //   48837e2010           | pushfd              

        $sequence_4 = { 660fbae6c5 480fbffd 488bdd 458bd2 415a 66440fa3f7 5f }
            // n = 7, score = 100
            //   660fbae6c5           | mov                 eax, dword ptr [esp + 0x2d0]
            //   480fbffd             | dec                 esp
            //   488bdd               | lea                 ebx, [0x380f2]
            //   458bd2               | dec                 esp
            //   415a                 | mov                 ecx, dword ptr [esp + 0x2d8]
            //   66440fa3f7           | nop                 word ptr [eax + eax]
            //   5f                   | dec                 ebp

        $sequence_5 = { 4863e8 eb02 8bfd 48833d????????00 4c8d0517110400 7415 0f1f440000 }
            // n = 7, score = 100
            //   4863e8               | dec                 eax
            //   eb02                 | mov                 ecx, dword ptr [ebp + 0x50]
            //   8bfd                 | dec                 eax
            //   48833d????????00     |                     
            //   4c8d0517110400       | add                 esp, 0x28
            //   7415                 | pop                 ebp
            //   0f1f440000           | pop                 ebx

        $sequence_6 = { e8???????? 488d0dd1a9fcff 48c1e602 0fb784b9c0f10300 488d91b0e80300 488d8d24030000 4c8bc6 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   488d0dd1a9fcff       | lea                 eax, [0x25e92]
            //   48c1e602             | inc                 esp
            //   0fb784b9c0f10300     | add                 eax, dword ptr [ecx + eax]
            //   488d91b0e80300       | mov                 eax, edi
            //   488d8d24030000       | rol                 eax, 0xa
            //   4c8bc6               | mov                 ebx, dword ptr [esp + 0x4c]

        $sequence_7 = { 48c1e810 0fb6d0 418bc0 48c1e808 0fb6c8 418bc2 458b8c96106d0500 }
            // n = 7, score = 100
            //   48c1e810             | mov                 ecx, esi
            //   0fb6d0               | inc                 ebp
            //   418bc0               | xor                 edi, edi
            //   48c1e808             | inc                 ebp
            //   0fb6c8               | xor                 ecx, ecx
            //   418bc2               | dec                 esp
            //   458b8c96106d0500     | mov                 dword ptr [esp + 0x30], edi

        $sequence_8 = { e8???????? 85c0 7505 8d7005 eb3a 41b816000000 488d15d43b0300 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   85c0                 | dec                 eax
            //   7505                 | lea                 ecx, [0x540b9]
            //   8d7005               | lea                 eax, [ecx + 1]
            //   eb3a                 | dec                 eax
            //   41b816000000         | mov                 ebx, dword ptr [ebx + ecx*8]
            //   488d15d43b0300       | cdq                 

        $sequence_9 = { 4533c8 4181e110101010 4933d1 488bc2 48c1e815 83e00f 448b9c87306d0400 }
            // n = 7, score = 100
            //   4533c8               | inc                 edx
            //   4181e110101010       | movzx               eax, byte ptr [eax + esi + 0x56310]
            //   4933d1               | shl                 eax, 8
            //   488bc2               | inc                 esp
            //   48c1e815             | xor                 ecx, eax
            //   83e00f               | inc                 ecx
            //   448b9c87306d0400     | mov                 eax, edx

    condition:
        7 of them and filesize < 19536896
}
Download all Yara Rules