AdverCRow is a group named by S2W that has been active since at least June 2023, and attempts to gain initial access through malvertising and then gains initial access through the Nitrogen malware.
Nitrogen
Nitrogen is a Windows-focused malware family that emerged in 2023 as an initial-access loader distributed through search-engine malvertising campaigns impersonating legitimate business and IT software.
Nitrogen
Family profile
Nitrogen is a Windows-focused malware family that emerged in 2023 as an initial-access loader distributed through search-engine malvertising campaigns impersonating legitimate business and IT software. Trojanized installers use DLL sideloading and a bundled Python environment to establish persistent access, retrieve command-and-control payloads, and deploy post-exploitation tooling including Meterpreter, Sliver, and Cobalt Strike. Observed operators used privilege-escalation and security-evasion mechanisms, performed host and domain reconnaissance, moved laterally using administrative remote-execution mechanisms, and exfiltrated data before ransomware deployment. Nitrogen activity has been linked to ALPHV/BlackCat affiliate intrusions. By mid-2024, the operators had developed an independent double-extortion ransomware operation using a strain reportedly derived from leaked Conti v2 builder code. The ransomware has affected organizations across manufacturing, business services, technology, and other sectors, including North American industrial operations. An ESXi-targeting variant contains a key-handling implementation defect that can make encrypted data unrecoverable even to the operators.
Capabilities
- Credential Theft
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Extortion
- Initial Access
- Lateral Movement
- Persistence
- Post Exploitation
- Privilege Escalation
- Process Injection
- Reconnaissance
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
Nitrogen in ATT&CK
28 distinct techniquesTechniques
28 techniquesReporting
Research mentioning Nitrogen
Ransomware payments fail to prevent repeat attacks, new data shows | brief | SC Media
Proofpoint survey data shows that paying ransomware demands often fails to end an incident and can expose victims to further extortion. Among affected UK organizations, 58% paid a ransom, and 22% of those payers were targeted again; globally, 54% of victim organizations paid and 37% were extorted a second time. The findings reinforce long-standing warnings that attackers may continue pressuring victims even after receiving payment. The reporting also found that payment does not guarantee recovery: 2% of victims that paid never got their files back, underscoring that criminals may withhold working decryptors or retain stolen data. Coverage cited the LockBit takedown under Operation Cronos as evidence that ransomware operators can keep victim information after payment, while noting that AI is increasingly improving the phishing, credential theft, impersonation, and reconnaissance activity that often precedes ransomware attacks.