Md5
6 total3dbd3c04b1acab0b70546e48d39247b71b637a43abca552acaee11c01913db18834d94cf35d9417aa93a5cb350a756e97e043d880dcf7889c6767ab97764769c3139c8e0d0dd9683ebfecdb2e4f1b6bba9297a8acbee74ba0169333ee38be2ef
Nitrogen is a malware cluster associated with two closely related roles over time: an initial-access malware chain used to compromise enterprise environments and a later independent ransomware operation.
Profile source: Mallory opens in a new tabNitrogen
Nitrogen is a malware cluster associated with two closely related roles over time: an initial-access malware chain used to compromise enterprise environments and a later independent ransomware operation. The activity first emerged in 2023 as a loader-style intrusion set used to deliver follow-on payloads including BlackCat/ALPHV, and by mid-2024 it had evolved into a standalone double-extortion ransomware actor operating its own strain. Reporting also links the ransomware codebase to leaked Conti v2 builder material.
As an initial-access malware, Nitrogen has been distributed through malvertising and fake software download campaigns. Operators used sponsored search results and spoofed software sites impersonating widely used business tools to lure victims into downloading trojanized installers. The infection chain on Windows has included DLL sideloading, installation of a malicious Python-based component, persistence via autorun mechanisms, staging of a loader component, and deployment of Meterpreter and Cobalt Strike for hands-on-keyboard follow-on activity. This access pattern has been assessed as a precursor to broader enterprise compromise, data theft, and ransomware deployment.
As ransomware, Nitrogen targets enterprise environments including VMware ESXi hypervisors and has been observed in attacks affecting manufacturing, technology, business services, finance, education, and other sectors, with repeated reporting on North American victims. The operation conducts double-extortion by stealing data in addition to encrypting systems. Public reporting has associated Nitrogen with incidents affecting major manufacturers, including Foxconn, and with victimology spanning the United States and Canada among other countries.
Nitrogen’s tooling has notable implementation flaws. Its ESXi variant contains a cryptographic bug that corrupts part of the public key used during encryption, making decryption impossible even for the operators. Multiple reports state that some victims could not recover data even after payment because the decryptor or key material was defective. This weakness is significant operationally because it undermines the gang’s ability to provide working decryption.
Nitrogen is best understood as a financially motivated intrusion and ransomware ecosystem that combines malvertising-based initial access, stealthy post-compromise tooling, persistence, staged payload delivery, and data-theft-backed extortion. The same name has been used both for the earlier access malware and for the later ransomware operation, and the two are consistently linked in reporting.
3dbd3c04b1acab0b70546e48d39247b71b637a43abca552acaee11c01913db18834d94cf35d9417aa93a5cb350a756e97e043d880dcf7889c6767ab97764769c3139c8e0d0dd9683ebfecdb2e4f1b6bba9297a8acbee74ba0169333ee38be2ef088B7708F2C1557B6023B1102FFC5C36C023FF4883CB073F26A33B73832C9268993ED58B817EC1DD64D0994AEAA297225CD94D1A6842819C74319A85350913AB9A82678C001EB09B71214D6646CA5EEC55A16767B7F8293DB18F753D1BF60C536747EFD115035DDA40948427E1DDFD107F03620C7A54EC212FB482A684BA74381C3623CCE4D0E27FAE348688F65E0F0F6B6A149790D1AE7DReported operators
AdverCRow is a group named by S2W that has been active since at least June 2023, and attempts to gain initial access through malvertising and then gains initial access through the Nitrogen malware.
MITRE ATT&CK
Reporting
Proofpoint survey data shows that paying ransomware demands often fails to end an incident and can expose victims to further extortion. Among affected UK organizations, 58% paid a ransom, and 22% of those payers were targeted again; globally, 54% of victim organizations paid and 37% were extorted a second time. The findings reinforce long-standing warnings that attackers may continue pressuring victims even after receiving payment. The reporting also found that payment does not guarantee recovery: 2% of victims that paid never got their files back, underscoring that criminals may withhold working decryptors or retain stolen data. Coverage cited the LockBit takedown under Operation Cronos as evidence that ransomware operators can keep victim information after payment, while noting that AI is increasingly improving the phishing, credential theft, impersonation, and reconnaissance activity that often precedes ransomware attacks.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.