Active Nitrogen campaign delivered via malicious ads for PuTTY, FileZilla
ID: 197f20e5-cabc-5184-85b1-4a01fe0a4b17
STIX ID: report--197f20e5-cabc-5184-85b1-4a01fe0a4b17
Feed Name: Malwarebytes Blog
**Executive Summary:** This report describes an active malvertising campaign targeting system administrators via fraudulent Google search ads that redirect victims to lookalike PuTTY/FileZilla installers; the Nitrogen malware is deployed via DLL sideloading (python311.dll) to achieve initial access, data theft, and enable BlackCat/ALPHV ransomware, and the report provides TTPs, IOCs (cloaking and lookalike domains, payload URLs, SHA256 hashes, and C2 IPs) plus mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
