Nitrogen ransomware is so broken even the crooks can't unlock your files
ID: 2ced7574-0742-58dc-ab0a-ada458a156a8
STIX ID: report--2ced7574-0742-58dc-ab0a-ada458a156a8
Feed Name: The Register (Security)
Threat Score
Coveware analysis found a critical bug in the Nitrogen group's VMware ESXi ransomware where a QWORD is loaded at rsp+0x1c overlapping and overwriting the public key loaded at rsp+0x20, corrupting the public key and preventing any decryptor (including one supplied by the criminals) from recovering encrypted files; Nitrogen has operated since 2023 and began active extortion in or around September 2024 but is not highly prolific.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
