Nitrogen is a financially motivated ransomware and intrusion operation first observed in 2023. It initially appeared as an opportunistic initial-access malware campaign that used search-engine malvertising and fake software installers to compromise enterprise users seeking common IT tools, then delivered second-stage tooling associated with post-compromise operations and, in some cases, ALPHV/BlackCat ransomware. By mid-2024, Nitrogen had evolved into an independent ransomware actor operating its own strain derived from leaked Conti 2 builder code and using a double-extortion model that combines data theft with encryption pressure. Nitrogen’s early intrusion activity relied on trojanized installers, DLL sideloading and preloading, Python-based loaders, scheduled-task persistence, privilege-escalation attempts, and in-memory execution of frameworks such as Cobalt Strike, Sliver, Meterpreter, and previously Pyramid C2. Reported post-compromise behavior includes reconnaissance, lateral movement using administrative tooling, credential-focused actions against privileged environments, data exfiltration, and deployment of ransomware payloads across Windows and VMware ESXi environments. The group has also been associated with AMSI, ETW, and WLDP bypasses, sleep obfuscation, and other defense-evasion measures. Victimology indicates a strong focus on North America, especially the United States, with repeated targeting of manufacturing and technology organizations and additional activity affecting financial institutions, real estate, non-profit entities, and other business sectors. Publicly reported victims and claimed victims include Foxconn, SRP Federal Credit Union, Red Barrels, and Pyramid. Foxconn’s North American operations were publicly linked to a major Nitrogen extortion event involving claims of large-scale data theft and operational disruption, illustrating the group’s emphasis on high-pressure attacks against supply-chain-relevant manufacturers. Nitrogen is widely described as part of the post-Conti ransomware ecosystem and has been linked in reporting to Eastern European infrastructure and Russian nationals. It has also been associated with operational and cryptographic implementation flaws, including defective decryption behavior in its ESXi tooling that can render victim data unrecoverable even if a ransom is paid. Known aliases center on the same naming convention, including Nitrogen ransomware and Nitrogen gang.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group reported targeting Foxconn.
Threat actor/group referenced through its ransomware tooling, which suffered a decryption design flaw similar to Sicarii, rendering recovery impossible.
Conducting a ransomware attack against Pyramid, a US real estate company.
Conducting ransomware intrusions and data theft against manufacturing targets, including Foxconn, and publicly claiming large-scale exfiltration of sensitive technical records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.