Skip to content
Nitrogen Ransomware: ESXi malware has a bug!

Nitrogen Ransomware: ESXi malware has a bug!

Coveware Bill Siegel February 2, 2026

Nitrogen ransomware was derived from the previously leaked Conti 2 builder code, and is similar to Nitrogen ransomware, but a coding mistake in the ESXi malware causes it to encrypt all the files with the wrong public key, irrevocably corrupting them. This means that even the threat actor is incapable of decrypting them, and that victims that are without viable backups have no ability to recover their ESXi encrypted servers. Paying a ransom will not assist these victims, as the decryption key/ tool will not work.

Extracted Entities

Attack Types (1)

Ransomware Groups (2)