Nitrogen is a Windows-focused malware family first observed in 2023 as an initial-access payload delivered through search-engine malvertising and fake software download sites. Early campaigns impersonated widely used business and IT tools and distributed trojanized installers that used DLL sideloading, DLL preloading, and bundled Python components to establish execution while presenting a legitimate decoy application to the victim. Nitrogen established persistence, contacted attacker-controlled infrastructure over multiple protocols, and deployed follow-on tooling including Meterpreter, Sliver, and Cobalt Strike to support hands-on-keyboard intrusion activity. Observed post-compromise behavior included reconnaissance, privilege escalation attempts, lateral movement, data exfiltration, and preparation for ransomware deployment. Multiple investigations linked Nitrogen intrusions to ALPHV/BlackCat affiliate activity, and some incidents progressed from initial access to ransomware execution in a short time.
By mid-2024, Nitrogen was also identified as an independent ransomware operation. Reporting associates the group’s ransomware with leaked Conti 2 builder code and describes double-extortion activity against organizations in sectors including manufacturing, business services, technology, hospitality, education, utilities, and finance, with victims notably concentrated in North America. Public reporting has tied the operation to attacks affecting Foxconn’s North American facilities and to ransomware variants targeting VMware ESXi environments.
Nitrogen has been repeatedly associated with malvertising-driven compromise chains that target business users searching for legitimate software. The malware’s installer and stager components have been observed using stealth and defense-evasion measures such as export forwarding, obfuscation, AMSI bypass, ETW bypass, WLDP bypass, sleep obfuscation, and process injection techniques including transacted hollowing. Persistence has been achieved through scheduled tasks and autorun mechanisms. Follow-on operator activity has included use of administrative tools and remote execution utilities for lateral movement and deployment.
The ransomware side of Nitrogen has also been notable for implementation flaws. Public reporting states that some ESXi-focused variants contained cryptographic or key-handling errors that made decryption impossible even for paying victims, undermining the reliability of the operators’ decryptor. Overall, Nitrogen is best understood as both an initial-access malware ecosystem and a later ransomware brand, with the strongest early evidence centering on its role as a malvertising-delivered loader used to stage enterprise intrusions that could culminate in ransomware and extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AdverCRow is a group named by S2W that has been active since at least June 2023, and attempts to gain initial access through malvertising and then gains initial access through the Nitrogen malware.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Affiliates of the ALPHV/BlackCat ransomware-as-a-service operation are turning to malvertising campaigns to establish an initial foothold in their victims' systems. Paid adverts for popular business software such as Slack and Cisco AnyConnect are being used to lure corporate victims into downloading malware
MITRE TTPs identified in this analysis T1583.001: Acquire Infrastructure: Domains
The observed infection chain starts with malvertising via Google and Bing Ads to lure users to compromised WordPress sites and phishing pages impersonating popular software distribution sites, where they are tricked into downloading trojanized ISO installers.
Further on, threat actors utilized PsExec, and WMIC for lateral movement
custom_installer.exe payload is responsible for decrypting another ZIP archive that contains additional payloads to be placed across multiple folders, as well as establishing a persistence mechanism via scheduled tasks.
The payloads zen.dll and fid.dll use the transacted hollowing technique
transacted hollowing is a technique that combines elements of both Process Hollowing and Process Doppelgänging
Using Python libraries allows attackers to more easily blend into an organization's normal traffic patterns since they are so ubiquitous. Added obfuscation techniques further delay defenders from spotting malicious activity.
The payloads zen.dll and fid.dll use the transacted hollowing technique
transacted hollowing is a technique that combines elements of both Process Hollowing and Process Doppelgänging
transacted hollowing is a technique that combines elements of both Process Hollowing and Process Doppelgänging
The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta. Analysis of the used aenys[.]com infrastructure identified Nitrogen malware disguised as a WinSCP installation file, which also distributes Cobalt Strike.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously seen ransomware variant mentioned as part of quarterly incident response activity.
An ESXi-targeting ransomware referenced as an example where a faulty decryptor prevented some victims from fully recovering files after payment.
A ransomware family with a VMware ESXi-targeting variant that reportedly overwrote its own public key, preventing decryption.
Ransomware tool affected by a cryptographic implementation error that rendered decryption ineffective and victim payment futile.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.