Nitrogen Loader

First seen
2022-03-15 00:00:00
Malware type
loader
Family
Malware family
Profile updated
2026-07-07 14:49:30

Targeted industries: financial-services technology-and-telecommunications

Context

Nitrogen Loader is a sophisticated malware framework used for deploying various malicious payloads. It primarily targets industries with high-value data, such as financial services and technology sectors. The loader is known for its modular architecture, allowing cybercriminals to customize attack vectors effectively.

Detection coverage

  • 1 YARA rules

Detection rules

  • CAPE_Nitrogenloaderbypass (yara-rule)

Reports & references

  • thedfirreport.com — Nitrogen Campaign Drops Sliver And Ends With Blackcat Ransomware (report)
  • esentire.com — Nitrogen Campaign 2 0 Reloads With Enhanced Capabilities Leading To Alphv Blackcat Ransomware (report)
  • nextron-systems.com — Nitrogen Dropping Cobalt Strike A Combination Of Chemical Elements (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nitrogen (report)
  • labs.withsecure.com — W Intel Research Keepass Trojanised Malware Campaign (report)
  • news.sophos.com — Into The Tank With Nitrogen (report)
  • esentire.com — Persistent Connection Established Nitrogen Campaign Leverages Dll Side Loading Technique For C2 Communication (report)

External references