Group profile
nitrogen
Nitrogen began as a malware loader in 2023 used to deliver BlackCat/ALPHV ransomware, then evolved into a fully independent ransomware operator by mid-2024, operating its own strain derived from leaked Conti 2 builder code and conducting double-extortion attacks primarily linked to Eastern European infrastructure.
Sectors hit
- Unspecified
Countries hit
MITRE ATT&CK · observed TTPs
- TA0001Initial Access
- T1189Drive-by Compromise
- TA0002Execution
- TA0003Persistence
- TA0004Privilege Escalation
- T1068Exploitation for Privilege Escalation
- TA0005Defense Evasion
- TA0006Credential Access
- T1003.001OS Credential Dumping: LSASS Memory
- TA0007Discovery
- TA0008Lateral Movement
- TA0009Collection
- T1119Automated Collection
- TA0010Exfiltration
- TA0011Command and Control