Nitrogen
Nitrogen is a ransomware group active since 2023. The content states it began as a malware loader used to deliver BlackCat/ALPHV ransomware and evolved into an independent ransomware operator by mid-2024. Its ransomware is described as derived from leaked Conti 2 builder code, with suspected links to the ALPHV/BlackCat ecosystem, and the group conducts double-extortion attacks. The content links Nitrogen primarily to Eastern European infrastructure and separately reports that it is linked to Russian nationals, including reporting that it is believed to be run by a Russian national. The group has targeted organizations in manufacturing, construction, and technology, with victim-sector data in the content also listing manufacturing, business services, technology, consumer services, and hospitality/tourism. Country distribution in the content is led by the United States, followed by Canada, with additional victims in Portugal, Taiwan, and France. Named victims in the content include Foxconn, ENENSYS Technologies, PCCA, Coweta County School System, SRP Federal Credit Union, and Red Barrels. Nitrogen is described as prioritizing data theft and extortion pressure, including double-extortion and, in some reporting, extortion-focused operations where encryption is absent or secondary. Reported access and post-compromise techniques in the content include PowerShell, scheduled tasks, LSASS memory credential dumping, RDP, SMB/Windows Admin Shares, automated collection, automated exfiltration, and exfiltration over C2 channels. Additional reporting in the content says Nitrogen commonly gains entry through compromised VPNs, remote desktop access, or phishing targeting IT administrators, and that it impersonates real companies to purchase official licenses for EDR and other security products through lightly vetted resellers. The content repeatedly associates Nitrogen with attacks on Foxconn’s North American operations, where the group claimed to have stolen about 8 TB of data and more than 11 million files and posted the company on its leak site. The allegedly stolen material was described as including confidential instructions, project documentation, drawings, schematics, and related files tied to major technology companies including Apple, Intel, Google, Nvidia, Dell, and AMD. A notable characteristic directly mentioned in the content is that Nitrogen’s VMware ESXi ransomware contains a coding flaw that corrupts the encryption public key, making decryption impossible even for the attackers. Multiple reports cited in the content state that victims may be unable to recover encrypted data even after paying. The content also notes ransom note filenames READ_ME_.TXT and readme.txt, and references an ESXi-targeting variant affecting hypervisors. No additional aliases or sub-groups are directly supported in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Capital Goods
- Commercial & Professional Services
- Software & Services
- Consumer Services
- Health Care Equipment & Services
- Materials
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇨🇦 Canada
- 🇵🇹 Portugal
- 🇹🇼 Taiwan
- 🇫🇷 France
Tradecraft
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Observables
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting ransomware intrusions and data theft against manufacturing targets, including Foxconn, and publicly claiming large-scale exfiltration of sensitive technical records.
Conducting extortion-focused intrusions involving large-scale theft of internal files, technical drawings, project documentation, and confidential manufacturing information, with encryption absent or secondary.
Conducting a ransomware and data exfiltration attack against Foxconn's North American facilities, claiming theft of large volumes of sensitive corporate and client data.
Ransomware operations targeting manufacturing, construction, and technology organizations; in this case, claiming responsibility for the Foxconn attack and using data theft plus encryption for extortion.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.