Nitrogen, also known as the Nitrogen gang or Nitrogen ransomware group, is a financially motivated cybercriminal operation first observed in 2023. Its early activity involved a namesake malware loader used in attacks that deployed ALPHV/BlackCat ransomware. By 2024, the operation was using its own ransomware derived from leaked Conti builder code. Nitrogen conducts double-extortion attacks, combining data theft and encryption with threats to publish stolen information on a dedicated leak site. Its ransomware targets Windows and VMware ESXi environments. Nitrogen's initial-access campaigns have used Google and Bing malvertising to lure users searching for legitimate IT utilities, including WinSCP, AnyDesk, Cisco AnyConnect, and TreeSize Free. Impersonated software-distribution sites deliver trojanized ISO installers containing legitimate decoy applications and malicious components. The infection chains employ DLL sideloading and preloading, Python-based loaders, and persistence through scheduled tasks and autorun mechanisms. Observed activity includes attempted privilege escalation through a CMSTPLUA UAC bypass, process injection using transacted hollowing, and defense evasion through AMSI, ETW, and WLDP bypasses, unhooking, and sleep obfuscation. Operators have deployed Meterpreter, Cobalt Strike, and Sliver for command-and-control and post-exploitation. Hands-on activity includes domain and administrator reconnaissance, credential discovery, lateral movement using PsExec, WMIC, and administrative shares, and data exfiltration with Restic. Targets include manufacturing, construction, technology, financial services, real estate, and non-profit organizations, with substantial activity in the United States and Canada. Named victims include Foxconn's North American operations, Canadian game developer Red Barrels, SRP Federal Credit Union, and U.S. real estate company Pyramid. Foxconn confirmed operational disruption following an intrusion claimed by Nitrogen, but did not substantiate the group's claimed volume of stolen data. Technical analysis of a Nitrogen ESXi ransomware variant identified a public-key corruption defect that can render encrypted data irrecoverable even when attackers possess their decryption material.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group reported targeting Foxconn.
Threat actor/group referenced through its ransomware tooling, which suffered a decryption design flaw similar to Sicarii, rendering recovery impossible.
Conducting a ransomware attack against Pyramid, a US real estate company.
The nitrogen ransomware group claims Pyramid as a victim, identifying it as a US real estate/construction-related company involved in shopping center ownership, management, development, redevelopment, and leasing. The post provides basic victim profiling and a source link but does not state any ransom amount, deadline, data volume, or proof of stolen data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.