Skip to content

nitrogen

Inactive

25 tracked victims · First seen Mar 29, 2023 · Last seen Jun 3, 2026

About

Aggregated threat-intel description

Nitrogen began as a malware loader in 2023 used to deliver BlackCat/ALPHV ransomware, then evolved into a fully independent ransomware operator by mid-2024, operating its own strain derived from leaked Conti 2 builder code and conducting double-extortion attacks primarily linked to Eastern European infrastructure.

Sectors: Manufacturing, Business Services, Technology · Countries: US, CA, PT

Recent victims

View all →
VictimSectorCountryPostedStatus
PyramidNot FoundUSJun 3, 2026
ENENSYS TechnologiesTechnologyFRMar 19, 2026
DeWalch Technologies, IncTechnologyUSFeb 18, 2026
PCCAHealthcareUSFeb 10, 2026
LumioDentalHealthcareUSFeb 5, 2026
QualiChem MetalworkingManufacturingUSJan 27, 2026
Connor CoNot FoundJan 27, 2026
DurashilohNot FoundJan 19, 2026
Whitfield Welding IncManufacturingCAJan 19, 2026
Walters Group IncNot FoundUSDec 16, 2025
AvtechTyeeTechnologyUSDec 5, 2025
Golden Artist ColorsManufacturingUSDec 3, 2025
Black Hills BentoniteManufacturingUSNov 6, 2025
Phillips Printing CompanyManufacturingOct 29, 2025
Heffner Toyota & LexusConsumer ServicesCASep 12, 2025
Ocean Edge Resort & Golf ClubHospitality and TourismUSAug 20, 2025
F&P Georgia Mfg IncManufacturingUSAug 6, 2025
Palm Bay InternationalNot FoundUSJul 23, 2025
C3 GroupNot FoundJul 16, 2025
Progressive Auto GroupConsumer ServicesUSJul 15, 2025
Kirkor Architects and PlannersBusiness ServicesCAJul 3, 2025
Coweta County School SystemEducationUSMay 24, 2025
Seneca Gaming & EntertainmentHospitality and TourismUSApr 26, 2025
Stadtwerke Schwerte GmbHEnergyDEApr 25, 2025
M'AR De AR HotelsHospitality and TourismPTApr 25, 2025

All ransomware groups · Dark web intelligence