Nitrogen began as a malware loader in 2023 used to deliver BlackCat/ALPHV ransomware, then evolved into a fully independent ransomware operator by mid-2024, operating its own strain derived from leaked Conti 2 builder code and conducting double-extortion attacks primarily linked to Eastern European infrastructure. Known victims: 46 2 ransom note(s) on file
Objectives
Executive Summary
Nitrogen is a medium-sophistication cybercriminal threat group initially identified as a malware loader in 2023, evolving into an independent ransomware operator by mid-2024. Specializing in double-extortion attacks and leveraging Eastern European infrastructure, Nitrogen operates its own strain derived from leaked Conti 2 builder code.
Goals & Targeting
Nitrogen's strategic objectives are centered on maximizing financial gains through ransomware campaigns. The group targets sectors tied to Eastern European critical infrastructure, likely due to higher payouts and potential for coercion. Their targeting profile reflects a focus on organizational vulnerabilities that facilitate quick payment of ransoms after encryption.
Enhanced Description
Nitrogen emerged as a malware loader delivering BlackCat/ALPHV ransomware before evolving into an independent operator by mid-2024. The group developed its own ransomware strain using leaked Conti 2 builder code, focusing on double-extortion tactics and targeting primarily Eastern European infrastructure. Known for its criminal motivations centered around financial gain, Nitrogen has been active since March 2023 through June 2026, with over 46 known victims and at least two ransom notes recovered.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Nitrogen has conducted multiple campaigns targeting ENENSYS Technologies, FOXCONN, and Pyramid. Activities include spear-phishing with malicious Office files and double-extortion attempts. Campaign patterns suggest a structured operational approach with significant overlap in Eastern European sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Nitrogen's operational timeline and ransomware capabilities, though specific TTPs and MITRE mappings remain partial.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
3
Campaigns
6
IOCs
0
Observed Data
0
Tactics