# Nightspire claims Uruguay notary association breach

Published: 2026-10-08 · Severity: high
Canonical: https://vorant.io/reports/4f4e369e-8c0e-5932-9e13-6eb1604de885/nightspire-claims-uruguay-notary-association-breach

> Ransomware group Nightspire listed Asociación de Escribanos del Uruguay as a victim, citing exposed FortiOS SSL-VPN credentials from the FortiBleed flaw.

Ransomware.live's tracker recorded a new victim post by the Nightspire ransomware group targeting the Asociación de Escribanos del Uruguay (Uruguay's Notaries Association). The listing notes 152 compromised user accounts and ten external attack-surface findings, with no reported compromised employee or third-party credentials at this time.

Notably, the victim's domain had FortiOS SSL-VPN credentials previously exposed through the FortiBleed vulnerability (CVE-2022-40684), a critical authentication-bypass flaw in Fortinet FortiOS/FortiProxy that allows unauthenticated attackers to read arbitrary files, including credential stores, via crafted HTTP/HTTPS requests. This suggests initial access or credential compromise may trace back to unpatched Fortinet infrastructure, a known and heavily abused entry vector for ransomware operators since its 2022 disclosure.

Defenders, particularly organizations still running vulnerable FortiOS/FortiProxy versions, should prioritize patching CVE-2022-40684, rotate any SSL-VPN credentials that may have been exposed historically, and review VPN access logs for anomalous authentication from this period. This is a single-victim listing rather than a broad campaign report, but it reinforces that FortiBleed-derived credential leakage remains a live risk factor for ransomware intrusions years after disclosure.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: nightspire
- Malware: NightSpire

## Detection guidance (public sample)

### Shadow Copy Deletion or Recovery Inhibition Typical of Ransomware

ATT&CK: T1486

Deletion of volume shadow copies or disabling of Windows recovery, commonly run immediately before ransomware encryption. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Shadow Copy Deletion or Recovery Inhibition Typical of Ransomware
description: Detects commands that delete volume shadow copies or disable Windows
  boot recovery, which ransomware operators run before encrypting data. The report
  does not describe the encryption stage, so this is a generic precursor detection
  for the T1486 outcome.
tags:
- attack.impact
- attack.t1486
- attack.t1490
logsource:
  category: process_creation
  product: windows
detection:
  selection_vss:
    Image|endswith: \vssadmin.exe
    CommandLine|contains|all:
    - delete
    - shadows
  selection_wmic:
    Image|endswith: \wmic.exe
    CommandLine|contains|all:
    - shadowcopy
    - delete
  selection_bcdedit:
    Image|endswith: \bcdedit.exe
    CommandLine|contains|all:
    - recoveryenabled
    - 'no'
  condition: 1 of selection_*
falsepositives:
- Backup or storage maintenance scripts that purge shadow copies
- Administrators reclaiming disk space with vssadmin
level: medium
id: c81de9da-3301-5d7f-92e2-795859ee7977
status: experimental
author: Vorant
references:
- https://www.ransomware.live/id/QXNvY2lhY2nDs24gZGUgRXNjcmliYW5vcyBkZWwgVXJ1Z3VheUBuaWdodHNwaXJl
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

1 more detection for this report is in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://www.ransomware.live/id/QXNvY2lhY2nDs24gZGUgRXNjcmliYW5vcyBkZWwgVXJ1Z3VheUBuaWdodHNwaXJl

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4f4e369e-8c0e-5932-9e13-6eb1604de885/nightspire-claims-uruguay-notary-association-breach.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
