Night Sky Ransomware recently emerged, on December 28, 2021 to be exact, making attacks on two large companies, one of which is TGC (Tokyo Computer Service) one of Japan’s largest computer companies and AKIJ Group, one of the largest industrial conglomerates in Blangadesh.

TGC’s servers that were hit by ransomware contained employee data and other confidential files. According to the group, all the files were encrypted and a portion extracted to be used as blackmail.

Night Sky uses strategies to pressure the victim to pay the ransom as soon as possible, these tactics are used as psychological pressure so that the victim sees no way out other than paying the ransom. But, the truth is that paying the ransom is not the only way out, there are companies that specialize in recovering files encrypted by ransomware, among them is Digital Recovery.

Payment is always discouraged by government authorities, ransom payments fund new attacks. There is no guarantee that after payment the key will actually be released. Therefore, never opt for payment.

Night Sky ransomware uses a combination of AES and RSA algorithms for data encryption, this combination is extremely strong and complex. The extension .nightsky is added to all encrypted files.

Night Sky spreads through unsecured RDP setups, spam and malicious email attachments, phishing, fake downloads, botnets, exploits, malicious ads, web injection, fake updates, repackaged and infected installers.

