Nitrogen/Azote
Unknown — assessed financially motivated criminal actor; suspected Eastern European based on targeting patterns and operational language artefacts · Financial extortion — initial access brokering and ransomware affiliate
Tactics, Techniques & Procedures (TTPs)
- Malvertising via legitimate Google Ads and Microsoft Advertising platforms — ads for popular IT software (WinSCP, AnyDesk, Notepad++, PuTTY, Advanced IP Scanner)
- Typosquatted or lookalike landing pages cloning legitimate software download sites
- Signed MSIX package delivery with certificates from legitimate code-signing sources — bypasses AV trust checks
- Decoy installer component installs functional software to reduce victim suspicion
- Python stager executing from APPDATA paths downloading Cobalt Strike shellcode
- In-memory Cobalt Strike beacon injection into legitimate Windows processes
- Extended dwell time (2-6 weeks) for systematic data exfiltration before ransomware deployment
- ALPHV/BlackCat RaaS affiliate for final-stage ransomware
Known Targets
Analyst Notes
The Nitrogen malvertising campaign emerged in 2023 as a distinct initial access brokering model using paid search advertisements rather than phishing or technical exploitation. The operation rebranded internally as Azote while maintaining the same malvertising methodology. The Foxconn North America breach — 8TB exfiltrated, approximately 11 million files including manufacturing schematics and customer contracts — is the most significant confirmed operation attributed to the group. The attack chain is notable for targeting IT professionals specifically (software titles commonly downloaded by admins) and for the patience of the data exfiltration phase before ransomware deployment. ALPHV/BlackCat disruption in early 2025 appears to have redirected affiliate relationships rather than stopped operations.
Also Known As
MITRE ATT&CK Techniques