Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors nitrogen

Description

Nitrogen began as a malware loader in 2023 used to deliver BlackCat/ALPHV ransomware, then evolved into a fully independent ransomware operator by mid-2024, operating its own strain derived from leaked Conti 2 builder code and conducting double-extortion attacks primarily linked to Eastern European infrastructure. Known victims: 46 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Nitrogen is a medium-sophistication cybercriminal threat group initially identified as a malware loader in 2023, evolving into an independent ransomware operator by mid-2024. Specializing in double-extortion attacks and leveraging Eastern European infrastructure, Nitrogen operates its own strain derived from leaked Conti 2 builder code.

Goals & Targeting

Nitrogen's strategic objectives are centered on maximizing financial gains through ransomware campaigns. The group targets sectors tied to Eastern European critical infrastructure, likely due to higher payouts and potential for coercion. Their targeting profile reflects a focus on organizational vulnerabilities that facilitate quick payment of ransoms after encryption.

Enhanced Description

Nitrogen emerged as a malware loader delivering BlackCat/ALPHV ransomware before evolving into an independent operator by mid-2024. The group developed its own ransomware strain using leaked Conti 2 builder code, focusing on double-extortion tactics and targeting primarily Eastern European infrastructure. Known for its criminal motivations centered around financial gain, Nitrogen has been active since March 2023 through June 2026, with over 46 known victims and at least two ransom notes recovered.

Key Capabilities

  • Independently operates its own ransomware strain
  • Leverages double-extortion tactics
  • Derived from leaked Conti 2 builder code
  • Proficient in TTPs including initial access, credential access, and data destruction

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Discovery
Collection
Exfiltration/Implantation
Impact

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1078.004
T1066

Software / Tooling

ALPHV Ransomware
Custom-built ransomware from Conti 2 builder code
Spear-phishing tools

Campaigns & Victims

Nitrogen has conducted multiple campaigns targeting ENENSYS Technologies, FOXCONN, and Pyramid. Activities include spear-phishing with malicious Office files and double-extortion attempts. Campaign patterns suggest a structured operational approach with significant overlap in Eastern European sectors.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • File hashes associated with Nitrogen malware: md5 values provided
  • Double extortion through data theft and encryption

Recommended Actions

  • Implement network segmentation to isolate critical systems
  • Regularly back up critical data off-line and test recovery processes
  • Monitor for activity associated with known Nitrogen IOCs
  • Enhance endpoint detection and response capabilities
  • Conduct employee training on phishing awareness

Suggested Tags

Criminal
Ransomware
Double Extortion
Critical Infrastructure
Eastern Europe

Confidence Assessment

High confidence in Nitrogen's operational timeline and ransomware capabilities, though specific TTPs and MITRE mappings remain partial.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

3

Campaigns

6

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Criminal
Double Extortion
Critical Infrastructure
Eastern Europe

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 29, 2023
Last Seen
Jun 3, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.