Hello. You have reached an Nightspire Support Chat.You need to know that dealing with us is the best choice to get back you infrastructure.
2026-02-03
Hello. So what exactly did you do and what do you want?
The amount you are asking for in that text file is going to be very difficult for us to do
All of your internal servers and virtual infrastructure have been encrypted by NIGHTSPIRE ransomware, and we have also copied your sensitive data.
Of course, we can provide you full file list we have.
And you can verify how decryption works correctly. Before paying, we will provide you decryption test to ensure your files decrypted correctly. After when you pay us, we will provide you decryption key & tools to decrypt by yourself.It takes only 6 hours to decrypt all your files and recover your infrastructure, even though your company's infra is big.
If you can see in above image, your company already listed as victim on our site. For your privacy, we hide your full name. If you make payment in 48 hours, we will decrypt your files, provide file deletion logs, and permanently delete your company on our website to protect your privacy.
But if you don't make payment in 48 hours, your company name will be released. And it may cause damage your company's reputation.
Ok I’ll collect some encrypted files. Waiting for that file list from you for now.
FileLists.zip : 478775KB
This is a list of files.You can send us three files that do not contain sensitive data for decryption testing.
Did you confirm the file list? If you intend to resolve this matter quickly, you must act within 48 hours. 12 hours have already passed. After the 48-hour deadline, the price will no longer be 6 BTC. It will increase to 8 BTC.
Well we cannot even afford 6 bitcoin so we will need to come to some arrangement since bitcoin is so expensive. We have reviewed the list. We are selecting mundane file names to have you reproduce. We are attaching some encrypted files to see you are able to unlock
https://limewire.com/[redacted]
Regarding payment, considering your company's annual revenue of $15 million, the initial ransom demand is only 3% of your revenue. Furthermore, since you stated you are willing to pay within 48 hours, we have already discounted the amount to 6 BTC, which is 2% of your revenue.
The default ransom demand is 5% of every company's revenue, but we have set it at 2% for your company. This is the best amount we can offer. I think you have to discuss this amount with your company management. We believe you can easily afford this amount. Let us know if you have any suggestions for a different amount. How much can you pay ?
Decrypted_files.zip : 1997701KB
This file is a decrypted version.
The IT team is reviewing the file you sent back. I should have file names back soon. Regarding price, It does not make sense to price off revenue for our business. We have very low margins and most of our money is locked up in inventory. I spoke with finance and between our current cash balance, payroll, and liabilities due, we can likely afford 2 to 3 bitcoin at its current price. Once we get comfortable with your promises we should be able to move quickly
If you pay within 6 hours, we can accept 3.5 BTC, and we will provide you with a decryption tool and key. However, if you fail to pay within 6 hours, you will be charged 6 BTC.This means that if you pay 3.5 BTC within 6 hours, the company's infrastructure can be restored. Because the decryption process is so fast, the company can resume operations within 8 hours.
That might be doable but will likely need a little more than 6 hours as we need to find a way to optain the bitcoin. We have already started the process of getting an exchange account so please just be patient there. And just to be clear, 3.5 bitcoin and you will give us a working decryptor tool, delete our data, and never attack or leak about us in the future?
Yes, if you pay within 6 hours, we will provide you with a decryption tool, key, and file deletion log. We will never attack again and will never leak any information about your company. Furthermore, once payment is completed, we will remove your company name (represented by an *) from our site. But remember, you have to make a payment in 6 hours from now on. After 6 hours, the amount will increase to 6 BTC.
We should be able to get it to you in 6 hours. In the meantime can you go ahead and unlock that file? Here is the other file you need. Also please produce these files from the file tree you gave us: [redacted].jpg , [redacted].jpeg, [redacted].png
Looks like we need a wallet for when we are ready?
ReqFiles.zip : 5103663KB
Here are the files you need: "[redacted].n*m" is the decrypted file. And you'll also required "[redacted].jpeg," "[redacted].png," and "[redacted].jpg."bc1q[redacted]
This is our wallet address. If you're ready, first send a test amount of less than $1,000 first, then send the remaining 3.5 BTC.
Should be ready to pay soon. After a test we will send you 3.5 bitcoin and you will provide what you promised. We'd also like to know how you did this attack so we can be more secure in the future.
Yes, we will. First, send a test amount of $100 to our wallet. Then, after confirming, please send 3.5 BTC.
1. We will provide you with a decryption tool and key. 2. We will provide you a permanently file deletion log. 3. We will inform you of how we accessed your internal network. 4. We will never attack again.
Test sent
0.00001000 BTC Received.
But it's now pending. Did you send 0.00001000 BTC?
Yes we did
Confirmed, Send us remain amount.Sent
Confirmed. We will send decryption tool & Key.
decryption.7z : 1761312KB
The password is [redacted].
[redacted] readme.7z : 486KBThis file is a description file on how to decrypt.
Thanks for instructions. will let you know how it goes and if we have any questions
We have already removed your company name (marked with *) from our blog site.
ok that was helpful... will keep you informed. Waiting for the rest of what you promised. Proof of deletion and how you did this to us? Thank you.
[redacted] file_deletion_log.zip : 274520KB
And we will never attack again, as we promised.
And about the init access, I'll give you a hand. [redacted].You will understand what I mean.