Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 1 actor

Nitrogen

Nitrogen is a malware family/name associated with both an initial access malware/loader and a later ransomware operation. Reporting states that Nitrogen first surfaced in 2023 as an initial access malware used in malvertising-driven intrusions, including campaigns abusing Google and Bing search ads and fake software download sites impersonating products such as AnyDesk, Cisco AnyConnect, TreeSize Free, and WinSCP. In those campaigns, victims downloaded trojanized ISO installers containing install.exe and a sideloaded malicious DLL (msi.dll, referred to as NitrogenInstaller). The chain installed the expected legitimate application to reduce suspicion, deployed a malicious Python package, created a registry Run key named Python for persistence, executed a malicious pythonw.exe every five minutes, and launched NitrogenStager via python.311.dll. NitrogenStager then contacted command-and-control infrastructure and deployed Meterpreter and Cobalt Strike Beacons. Sophos assessed this activity as staging for ransomware deployment, and Trend Micro previously linked a similar ad-driven intrusion chain to BlackCat/ALPHV ransomware. The campaign primarily targeted technology and non-profit organizations in North America, and other reporting also places Nitrogen among payloads used in malvertising against business users.

Multiple sources state that the threat actors behind Nitrogen later evolved into an independent ransomware operator by mid-2024. The ransomware strain is described as derived from leaked Conti 2 builder code and associated with double-extortion attacks. The group has been linked primarily to Eastern European infrastructure and has listed victims across sectors including manufacturing, business services, technology, hospitality, education, utilities, finance, and media. Reported victim geography includes a strong concentration in the United States, with additional victims in Canada, Portugal, Taiwan, and France. Public reporting cites organizations such as Foxconn, ENENSYS Technologies, PCCA, Coweta County School System, SRP Federal Credit Union, and Red Barrels as victims or claimed victims. Foxconn confirmed that several North American factories were affected by a cyberattack after Nitrogen listed the company on its leak site; Nitrogen claimed to have stolen about 8 TB of data and more than 11 million files, including confidential documents, project materials, and drawings tied to major customers.

Nitrogen ransomware includes a VMware ESXi-targeting variant. High-confidence reporting from Coveware and Veeam states that this ESXi encryptor contains a critical cryptographic implementation flaw that corrupts the public key used during encryption, including reports that part of the public key is overwritten with zeros or otherwise overwritten on the stack. As a result, encrypted ESXi files can become permanently unrecoverable, and decryption is impossible even for the operators with the private key. Several reports explicitly warn that paying the ransom will not restore affected ESXi data. The ransomware has also been described as sharing code lineage with Babuk-related codebases in some detections. Reported ransom note filenames include READ_ME_.TXT and readme.txt. ATT&CK-style behaviors attributed to the ransomware operation include PowerShell use, scheduled tasks, LSASS memory credential dumping, RDP, SMB/Windows Admin Shares, automated collection, automated exfiltration, and exfiltration over command-and-control channels.

Reported indicators associated with Nitrogen include the YARA rule nitrogen.yar and MD5 hashes 1b637a43abca552acaee11c01913db18, 3139c8e0d0dd9683ebfecdb2e4f1b6bb, 3dbd3c04b1acab0b70546e48d39247b7, 7e043d880dcf7889c6767ab97764769c, 834d94cf35d9417aa93a5cb350a756e9, and a9297a8acbee74ba0169333ee38be2ef. In the initial access/malvertising context, Nitrogen has been associated with fake software sites, compromised WordPress-hosted landing pages, geographic filtering, trojanized ISO installers, malicious DLL sideloading, Python-based persistence, Meterpreter, and Cobalt Strike.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
AdverCRow

AdverCRow is a group named by S2W that has been active since at least June 2023, and attempts to gain initial access through malvertising and then gains initial access through the Nitrogen malware.

via medium s2wblogmedium.com
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583Acquire InfrastructureEvidence3

AdverCRow is a group named by S2W that has been active since at least June 2023, and attempts to gain initial access through malvertising and then gains initial access through the Nitrogen malware.

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence1

From those fake sites, users download trojanized ISO installers ('install.exe'), which contain and sideload a malicious DLL file ('msi.dll').

T1566PhishingEvidence1

Clicking the link brings the visitor to compromised WordPress hosting pages that imitate the legitimate software download sites for the particular application.

Collection

1 technique
T1074Data StagedEvidence1

The Nitrogen ransomware gang says it stole 8 TB of data from Foxconn, including files allegedly tied to projects from Apple, Nvidia, Google, Dell, and Intel.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta. Analysis of the used aenys[.]com infrastructure identified Nitrogen malware disguised as a WinSCP installation file, which also distributes Cobalt Strike.

Exfiltration

1 technique
T1048Exfiltration Over Alternative ProtocolEvidence1

The alleged Foxconn cache includes technical files... the cache contains confidential instructions, project documentation, and technical drawings.

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence2

Nova, the affiliate program for ransomware crew RAlord, on Tuesday issued an apology to Eriell Group... The malware slingers claimed they didn’t encrypt any files... Pro-Russian hacktivist crew CyberVolk got sloppy when they debuted a ransomware service late last year. They hardcoded the master keys... thus allowing victims to recover encrypted data without paying any extortion fees. ... Sicarii encryptor generates a new cryptographic key pair during every execution... Similarly, a programming mistake in Nitrogen ransomware prevents the gang's decryptor from recovering victims' files

T1657Financial TheftEvidence1

By 2024, the hacking group had moved into direct extortion, claiming victims across sectors where stolen data can create pressure fast.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app11 months ago
ACTIVITY FEED

Recent activity

23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.