Nitrogen is a Windows-focused malware family that emerged in 2023 as an initial-access loader distributed through search-engine malvertising campaigns impersonating legitimate business and IT software. Trojanized installers use DLL sideloading and a bundled Python environment to establish persistent access, retrieve command-and-control payloads, and deploy post-exploitation tooling including Meterpreter, Sliver, and Cobalt Strike. Observed operators used privilege-escalation and security-evasion mechanisms, performed host and domain reconnaissance, moved laterally using administrative remote-execution mechanisms, and exfiltrated data before ransomware deployment. Nitrogen activity has been linked to ALPHV/BlackCat affiliate intrusions. By mid-2024, the operators had developed an independent double-extortion ransomware operation using a strain reportedly derived from leaked Conti v2 builder code. The ransomware has affected organizations across manufacturing, business services, technology, and other sectors, including North American industrial operations. An ESXi-targeting variant contains a key-handling implementation defect that can make encrypted data unrecoverable even to the operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AdverCRow is a group named by S2W that has been active since at least June 2023, and attempts to gain initial access through malvertising and then gains initial access through the Nitrogen malware.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Affiliates of the ALPHV/BlackCat ransomware-as-a-service operation are turning to malvertising campaigns to establish an initial foothold in their victims' systems. Paid adverts for popular business software such as Slack and Cisco AnyConnect are being used to lure corporate victims into downloading malware
MITRE TTPs identified in this analysis T1583.001: Acquire Infrastructure: Domains
The observed infection chain starts with malvertising via Google and Bing Ads to lure users to compromised WordPress sites and phishing pages impersonating popular software distribution sites, where they are tricked into downloading trojanized ISO installers.
Further on, threat actors utilized PsExec, and WMIC for lateral movement
custom_installer.exe payload is responsible for decrypting another ZIP archive that contains additional payloads to be placed across multiple folders, as well as establishing a persistence mechanism via scheduled tasks.
The payloads zen.dll and fid.dll use the transacted hollowing technique
transacted hollowing is a technique that combines elements of both Process Hollowing and Process Doppelgänging
Using Python libraries allows attackers to more easily blend into an organization's normal traffic patterns since they are so ubiquitous. Added obfuscation techniques further delay defenders from spotting malicious activity.
The payloads zen.dll and fid.dll use the transacted hollowing technique
transacted hollowing is a technique that combines elements of both Process Hollowing and Process Doppelgänging
transacted hollowing is a technique that combines elements of both Process Hollowing and Process Doppelgänging
The KeeLoader used in the attack installed Cobalt Strike, and its watermark, 678358251, was found to be indirectly related to BlackCat and BlackBasta. Analysis of the used aenys[.]com infrastructure identified Nitrogen malware disguised as a WinSCP installation file, which also distributes Cobalt Strike.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously seen ransomware variant mentioned as part of quarterly incident response activity.
An ESXi-targeting ransomware referenced as an example where a faulty decryptor prevented some victims from fully recovering files after payment.
A ransomware family with a VMware ESXi-targeting variant that reportedly overwrote its own public key, preventing decryption.
Ransomware tool affected by a cryptographic implementation error that rendered decryption ineffective and victim payment futile.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.