logo

Active Nitrogen campaign delivered via malicious ads for PuTTY, FileZilla

ID: 197f20e5-cabc-5184-85b1-4a01fe0a4b17

STIX ID: report--197f20e5-cabc-5184-85b1-4a01fe0a4b17

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2024-04-09

Date Updated: 2026-04-28

...
...

**Executive Summary:** This report describes an active malvertising campaign targeting system administrators via fraudulent Google search ads that redirect victims to lookalike PuTTY/FileZilla installers; the Nitrogen malware is deployed via DLL sideloading (python311.dll) to achieve initial access, data theft, and enable BlackCat/ALPHV ransomware, and the report provides TTPs, IOCs (cloaking and lookalike domains, payload URLs, SHA256 hashes, and C2 IPs) plus mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.