logo

Nitrogen Ransomware Attacks Encrypts Files With .NBA Extension

ID: 4f87953b-d1bd-57a9-8ccb-f3c37aa16544

STIX ID: report--4f87953b-d1bd-57a9-8ccb-f3c37aa16544

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-01-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Nitrogen is a recently observed ransomware campaign that uses malicious search ads to lure victims to fake installers for legitimate tools (e.g., AnyDesk, Cisco AnyConnect, WinSCP), which deploy a trojan that persists via registry keys, leverages Cobalt Strike and Meterpreter for lateral movement, encrypts files with a .NBA extension, and conducts double-extortion by threatening to publish stolen data; the activity has predominantly impacted manufacturing, financial services, and technology organizations in the USA, Canada, and the UK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.