Skip to content
← All Threat Actors
Cybercrime high Unknown (suspected Eastern Europe)

Nitrogen/Azote

Unknown — assessed financially motivated criminal actor; suspected Eastern European based on targeting patterns and operational language artefacts · Financial extortion — initial access brokering and ransomware affiliate

Reports 1
Active Since 2023
Last Reported 22 Jul 2026
Sectors Targeted manufacturing, professional-services, technology, finance

Tactics, Techniques & Procedures (TTPs)

  • Malvertising via legitimate Google Ads and Microsoft Advertising platforms — ads for popular IT software (WinSCP, AnyDesk, Notepad++, PuTTY, Advanced IP Scanner)
  • Typosquatted or lookalike landing pages cloning legitimate software download sites
  • Signed MSIX package delivery with certificates from legitimate code-signing sources — bypasses AV trust checks
  • Decoy installer component installs functional software to reduce victim suspicion
  • Python stager executing from APPDATA paths downloading Cobalt Strike shellcode
  • In-memory Cobalt Strike beacon injection into legitimate Windows processes
  • Extended dwell time (2-6 weeks) for systematic data exfiltration before ransomware deployment
  • ALPHV/BlackCat RaaS affiliate for final-stage ransomware

Known Targets

Manufacturing (Foxconn North America)Technology services companiesProfessional services firmsMid-market organisations 500-10,000 employees

Analyst Notes

The Nitrogen malvertising campaign emerged in 2023 as a distinct initial access brokering model using paid search advertisements rather than phishing or technical exploitation. The operation rebranded internally as Azote while maintaining the same malvertising methodology. The Foxconn North America breach — 8TB exfiltrated, approximately 11 million files including manufacturing schematics and customer contracts — is the most significant confirmed operation attributed to the group. The attack chain is notable for targeting IT professionals specifically (software titles commonly downloaded by admins) and for the patience of the data exfiltration phase before ransomware deployment. ALPHV/BlackCat disruption in early 2025 appears to have redirected affiliate relationships rather than stopped operations.

Also Known As

NitrogenAzoteNitrogenLoader operators