A proof-of-concept malware called NitroRansomware was published on GitHub and later observed being promoted as a fake tool for generating free Discord Nitro codes. Written in C#, the ransomware encrypts files in common user folders such as Documents, Desktop, and Pictures, appends the .givemenitro extension, changes the victim’s wallpaper, and displays a ransom note demanding a $9.99 Discord Nitro gift code within three hours instead of cryptocurrency. The malware validates submitted gift-code URLs through Discord’s API and forwards valid codes to an attacker-controlled Discord webhook before releasing a decryption key.
The malware also includes broader credential-theft and persistence features beyond file encryption. Reported capabilities include adding itself to startup, collecting host details such as username and system UUID, stealing Discord tokens from LevelDB files, attempting to harvest browser data from Chrome, Brave, and Yandex, grabbing IP information, and exfiltrating data through Discord webhooks. Researchers said the sample used an embedded static decryption key, meaning some victims could recover files without paying, but warned that affected users should immediately change their Discord password because account tokens may already be compromised.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported on NitroRansomware samples shared by MalwareHunterTeam, describing a strain distributed as a fake free Nitro generator that appends the .givemenitro extension, changes the wallpaper, and demands a $9.99 Discord Nitro gift code. The analysis also noted the malware validates gift codes via Discord's API, contains an embedded static decryption key, steals Discord tokens and browser data, and can execute commands and exfiltrate results through a Discord webhook.
A GitHub repository for NitroRansomware was published, describing a C# proof-of-concept ransomware that encrypts files and demands a Discord Nitro gift subscription for decryption. The repository also documented features including startup persistence, host data collection, token grabbing, IP grabbing, and Discord webhook logging.
An update to the BleepingComputer article added that NitroRansomware also steals information from browsers. The added detail expanded the known scope of data theft beyond Discord token theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.