Skip to content
The Nexus
Group profile0 claimed in last 30d2 total tracked

nitrogen

Forward this

Nitrogen began as a malware loader in 2023 used to deliver BlackCat/ALPHV ransomware, then evolved into a fully independent ransomware operator by mid-2024, operating its own strain derived from leaked Conti 2 builder code and conducting double-extortion attacks primarily linked to Eastern European infrastructure.

First seen: Jun 3 · 00:00 UTCLast seen: Jun 3 · 16:16 UTCTracked since: 2024-09-30
Sectors hit
  • Unspecified1
Countries hit
  • United States1
MITRE ATT&CK · observed TTPs11 tactics

Tactics and techniques attributed to NITROGEN by ransomware.live's curated TTP catalog. Identifiers link to the canonical MITRE ATT&CK reference for each tactic or sub-technique.

Recent claimed victims