logo

Nitrogen Campaign Drops Sliver and Ends With BlackCat Ransomware

ID: f0be50b2-f9ac-5b9c-a12c-71a10749e482

STIX ID: report--f0be50b2-f9ac-5b9c-a12c-71a10749e482

Feed Name: The DFIR Report

Threat Score
78/100

Date Published: 2024-09-30

Date Updated: 2026-04-19

Author: editor

...
...

A targeted ransomware intrusion began via a malvertising-driven Nitrogen campaign that delivered a trojanized Advanced IP Scanner installer; the loader sideloaded a modified python311.dll which launched Nitrogen payloads that dropped obfuscated Sliver and Cobalt Strike beacons (in-memory via Python scripts). The actor performed hands-on keyboard discovery, dumped LSASS credentials, moved laterally using Impacket/WMExec and SMB, exfiltrated file shares with Restic to a remote server in Bulgaria, and eight days after initial access reset a privileged backup account and deployed BlackCat ransomware across the domain by using PsExec, configuring Safe Mode boot and automatic logon to ensure encryption succeeded; the report includes extensive IOCs, C2 infrastructure, hashes, detection rules, and mapped ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.