Nightspire claims Uruguay notary association breach
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Ransomware group Nightspire listed Asociación de Escribanos del Uruguay as a victim, citing exposed FortiOS SSL-VPN credentials from the FortiBleed flaw.
Ransomware.live's tracker recorded a new victim post by the Nightspire ransomware group targeting the Asociación de Escribanos del Uruguay (Uruguay's Notaries Association). The listing notes 152 compromised user accounts and ten external attack-surface findings, with no reported compromised employee or third-party credentials at this time.
Notably, the victim's domain had FortiOS SSL-VPN credentials previously exposed through the FortiBleed vulnerability (CVE-2022-40684), a critical authentication-bypass flaw in Fortinet FortiOS/FortiProxy that allows unauthenticated attackers to read arbitrary files, including credential stores, via crafted HTTP/HTTPS requests. This suggests initial access or credential compromise may trace back to unpatched Fortinet infrastructure, a known and heavily abused entry vector for ransomware operators since its 2022 disclosure.
Defenders, particularly organizations still running vulnerable FortiOS/FortiProxy versions, should prioritize patching CVE-2022-40684, rotate any SSL-VPN credentials that may have been exposed historically, and review VPN access logs for anomalous authentication from this period. This is a single-victim listing rather than a broad campaign report, but it reinforces that FortiBleed-derived credential leakage remains a live risk factor for ransomware intrusions years after disclosure.
Mentioned in this report
Detection guidance
Shadow Copy Deletion or Recovery Inhibition Typical of Ransomware
Deletion of volume shadow copies or disabling of Windows recovery, commonly run immediately before ransomware encryption. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Shadow Copy Deletion or Recovery Inhibition Typical of Ransomware
description: Detects commands that delete volume shadow copies or disable Windows
boot recovery, which ransomware operators run before encrypting data. The report
does not describe the encryption stage, so this is a generic precursor detection
for the T1486 outcome.
tags:
- attack.impact
- attack.t1486
- attack.t1490
logsource:
category: process_creation
product: windows
detection:
selection_vss:
Image|endswith: \vssadmin.exe
CommandLine|contains|all:
- delete
- shadows
selection_wmic:
Image|endswith: \wmic.exe
CommandLine|contains|all:
- shadowcopy
- delete
selection_bcdedit:
Image|endswith: \bcdedit.exe
CommandLine|contains|all:
- recoveryenabled
- 'no'
condition: 1 of selection_*
falsepositives:
- Backup or storage maintenance scripts that purge shadow copies
- Administrators reclaiming disk space with vssadmin
level: medium
id: c81de9da-3301-5d7f-92e2-795859ee7977
status: experimental
author: Vorant
references:
- https://www.ransomware.live/id/QXNvY2lhY2nDs24gZGUgRXNjcmliYW5vcyBkZWwgVXJ1Z3VheUBuaWdodHNwaXJl
1 more detection for this report is in the app — the rules that match its indicators, plus every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. Three days of it free, no card.
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.ransomware.live/id/QXNvY2lhY2nDs24gZGUgRXNjcmliYW5vcyBkZWwgVXJ1Z3VheUBuaWdodHNwaXJl
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,978 reports from 148 sources, 471 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs