Nitrogen is an independent crime group operating its own ransomware strain derived from leaked Conti 2 builder code.
Analyst brief
Nitrogen started as a malware loader in 2023 delivering BlackCat/ALPHV ransomware, then evolved into an independent crime group by mid-2024 operating its own ransomware strain derived from leaked Conti 2 builder code. It primarily targets the Professional Services sector in the United States. The group employs double-extortion tactics and is associated with Eastern European infrastructure. Defenders should be wary of suspicious loaders from Eastern European IP ranges, maintain offline backups, and verify patches against exploitation techniques tied to the leaked Conti toolset.
nitrogen
activecrime
Nitrogen began as a malware loader in 2023 used to deliver BlackCat/ALPHV ransomware, then evolved into a fully independent ransomware operator by mid-2024, operating its own strain derived from leaked Conti 2 builder code and conducting double-extortion attacks primarily linked to Eastern European infrastructure.