Skip to content
skopnix
← adversaries
Unknown · assessed origin China

Nitro

Covert Grove
misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

These attackers were the subject of an extensive report by Symantec in 2011, which termed the attackers Nitro and stated: 'The goal of the attackers appears to be to collect intellectual property such as design documents, formulas, and manufacturing processes. In addition, the same attackers appear to have a lengthy operation history including attacks on other industries and organizations. Attacks on the chemical industry are merely their latest attack wave. As part of our investigations, we were also able to identify and contact one of the attackers to try and gain insights into the motivations behind these attacks.' Palo Alto Networks reported on continued activity by the attackers in 2014.

Assessed origin: China

assessed originobserved targets (0)

Observed targets

sectors · 1

Chemical

as stated by MISP galaxy / ransomware.live — not inferred

Primary-source reports
Take it with you
References
Early access

Track Nitro on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected