SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

nightspire

💰 eCrimeMotivation: financialLast active: 2026-09-21First seen: 2026-04-01
4
linked CVEs
Targeted industries
Business ServicesConsumer ServicesEnergyFinancial ServicesHealthcareHospitality and TourismManufacturingNot FoundTransportation/Logistics
Targeted regions
EGESFRGBMXTHTRUS
No description available.
Source: misp_galaxy · Collected: 2026-09-24
⚡ Vulnerabilities & Exploits4 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2024-55591
suspected

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CVSS 9.8
KEVransomware
CVE-2023-27532
suspected

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

KEVransomware
CVE-2024-37085
suspected

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

KEVransomware
CVE-2025-32463
suspected

Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.

KEV
🔍 Detection Coverage3 Sigma
Derived from linked CVEs — not a direct actor match
highvia CVE-2024-37085
Potential Exploitation of CVE-2024-37085 - Suspicious Creation Of ESX Admins Group
windows
highvia CVE-2024-37085
Potential Exploitation of CVE-2024-37085 - Suspicious ESX Admins Group Activity
windows
highvia CVE-2025-32463
Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
linux
🧬 YaraComing soon
🛰️ Infrastructure & IOCs10
md5efd5366eb7473d6f7fb97ec7ac59f09d—2026-06-02
md542c062d6299ca9f76554441a29429404—2026-06-02
md5d65c293efb5e6d033c83b2ac472bf0cb—2026-06-02
ip194.87.31.69—2026-06-02
md58901ce810f999f79c51c4d4f6c93fe6b—2026-06-02
sha25651b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2—2026-06-02
sha2562834114ff7e487c4ca3f50ca39f7d652dea1be98f885c388f01b6ff35309307b—2026-06-02
sha2563ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235—2026-06-02
sha256bde50a42efc079edde1a314243ad339db2d42e343fbbcd39117803b0f5960355—2026-04-07
sha256ad67031e2ca68764fe1a7d6632c02b02a299d59efb920710011a9a2ccf4399b7—2026-04-07
📰 Threat Intel Coverage2
Digest reports mentioning this actor (incl. aliases)
How Hastalamuerte Operates: Group-IB's Analysis of The Gentlemen's Attack Methodsmatched as Nightspire2026-06-02
Decoding NightSpire: Ransomware IOCs Aren't Set in Stone | Huntressmatched as NightSpire2026-04-07