Nitrogen is a financially motivated ransomware and extortion group active since 2023. It initially appeared as a malware loader associated with delivery of BlackCat/ALPHV payloads and later evolved into an independent ransomware operator by 2024. Reporting has linked its tooling to code derived from the leaked Conti 2 builder, placing it within the broader post-Conti criminal ecosystem. The group has been associated with infrastructure and operators linked to Eastern Europe, and some reporting has described links to Russian nationals, but attribution beyond that remains limited. Nitrogen operates a double-extortion model, combining data theft with encryption and threats to publish stolen information. In some incidents, its behavior has also aligned with extortion-first or data-theft-heavy operations in which exfiltration appears to be prioritized over disruptive encryption. Victimology indicates a concentration in manufacturing, technology, business services, construction, and other enterprise sectors, with a notable emphasis on North American organizations, especially in the United States and Canada. Public reporting also places it among ransomware actors targeting healthcare-related organizations during 2026. Observed tradecraft includes use of PowerShell, scheduled tasks, credential access against LSASS, lateral movement over SMB and administrative shares, use of Remote Desktop Protocol, automated collection, and automated exfiltration over command-and-control channels. Nitrogen has also been described as using impersonation of legitimate companies to fraudulently obtain licensed security products, including endpoint protection and EDR tooling, reflecting a tailored operational approach to weakening or bypassing defenses. The group has claimed intrusions against major manufacturers and other enterprises, including high-profile attacks affecting North American operations of large electronics manufacturers. Such incidents have been characterized by large-scale data theft claims involving engineering, project, and supply-chain-related information, underscoring Nitrogen’s focus on organizations where operational disruption and exposure of proprietary data can create strong extortion leverage. Nitrogen’s tooling has drawn attention for serious implementation flaws. Multiple analyses of its VMware ESXi-focused ransomware found a cryptographic bug that corrupts the public key used during encryption, making decryption impossible even for the attackers. This defect means victims may be unable to recover encrypted data through payment because no valid corresponding private key exists for the corrupted key material. The flaw has led some researchers to characterize affected Nitrogen incidents as effectively destructive rather than conventionally recoverable ransomware events. Known aliases are limited, and Nitrogen is primarily tracked under the single name Nitrogen. No high-confidence sub-groups are currently established in the available reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group reported targeting Foxconn.
Threat actor/group referenced through its ransomware tooling, which suffered a decryption design flaw similar to Sicarii, rendering recovery impossible.
Conducting a ransomware attack against Pyramid, a US real estate company.
Conducting ransomware intrusions and data theft against manufacturing targets, including Foxconn, and publicly claiming large-scale exfiltration of sensitive technical records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.