Nitrogen Loader
- First seen
- 2022-03-15 00:00:00
- Malware type
- loader
- Family
- Malware family
- Profile updated
- 2026-07-07 14:49:30
Targeted industries: financial-services technology-and-telecommunications
Context
Nitrogen Loader is a sophisticated malware framework used for deploying various malicious payloads. It primarily targets industries with high-value data, such as financial services and technology sectors. The loader is known for its modular architecture, allowing cybercriminals to customize attack vectors effectively.
Detection coverage
- 1 YARA rules
Detection rules
- CAPE_Nitrogenloaderbypass (yara-rule)
Reports & references
- thedfirreport.com — Nitrogen Campaign Drops Sliver And Ends With Blackcat Ransomware (report)
- esentire.com — Nitrogen Campaign 2 0 Reloads With Enhanced Capabilities Leading To Alphv Blackcat Ransomware (report)
- nextron-systems.com — Nitrogen Dropping Cobalt Strike A Combination Of Chemical Elements (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Nitrogen (report)
- labs.withsecure.com — W Intel Research Keepass Trojanised Malware Campaign (report)
- news.sophos.com — Into The Tank With Nitrogen (report)
- esentire.com — Persistent Connection Established Nitrogen Campaign Leverages Dll Side Loading Technique For C2 Communication (report)