logo

Nitrogen Ransomware Uses Cobalt Strike and Log Wiping in Targeted Attacks on Organizations

ID: eb426ae5-1ef7-518e-9402-b4b97c6ccbd6

STIX ID: report--eb426ae5-1ef7-518e-9402-b4b97c6ccbd6

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2025-04-30

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

This report documents a Nitrogen ransomware campaign that leveraged malvertising to push a fake WinSCP installer (SHA-256: fa3eca4d53a1b7c4cfcd14f642ed5f8a8a864f56a8a47acbf5cf11a6c5d2afa2) which used DLL sideloading to establish persistence via a NitrogenLoader and ultimately enabled BlackCat ransomware deployment; investigators observed Cobalt Strike beacons, log clearing, suspicious executables, and multiple forensic artifacts used to trace lateral movement and command-and-control activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.