New Nitrogen Ransomware Targets Financial Firms in the US, UK and Canada

May 21, 2025, 9:54 p.m.

Description

Nitrogen, a new ransomware strain identified in September 2024, has become a significant threat to organizations worldwide, particularly in the financial sector. It encrypts critical data and demands substantial payments for decryption, targeting industries such as finance, construction, manufacturing, and technology in the United States, Canada, and the United Kingdom. The ransomware's attack chain begins with malvertising campaigns on search engines, tricking users into downloading trojanized installers. It uses tools like Cobalt Strike and Meterpreter shells to establish persistence and move laterally within networks. Notable victims include SRP Federal Credit Union, Red Barrels, Control Panels USA, and Kilgore Industries. Nitrogen employs sophisticated tactics, including system reconnaissance, advanced evasion techniques, and exploitation of vulnerable drivers to disable security tools.

Date

  • Created: May 20, 2025, 7:27 p.m.
  • Published: May 20, 2025, 7:27 p.m.
  • Modified: May 21, 2025, 9:54 p.m.

Indicators

  • 55f3725ebe01ea19ca14ab14d747a6975f9a6064ca71345219a14c47c18c88be
  • bfc2ef3b404294fe2fa05a8b71c7f786b58519175b7202a69fe30f45e607ff1c

Attack Patterns

Additional Informations

  • Finance
  • Canada
  • United Kingdom of Great Britain and Northern Ireland
  • United States of America