# Nitrogen

> As of 2026-07-27, Nitrogen is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning ransomware. Also known as LockBit, Nitrogen Group, Nitrogen Operators, Nitrogen Ransomware. ATT&CK coverage spans 78 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1018 (Remote System Discovery), T1021 (Remote Services).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** RANSOMWARE
- **Also known as:** LockBit, Nitrogen Group, Nitrogen Operators, Nitrogen Ransomware
- **As of:** 2026-07-27

## ATT&CK techniques observed

78 techniques observed across 2 of 2 tracked threats. Tactics: Discovery (13), Stealth (formerly Defense Evasion) (11), Execution (10), Persistence (6), Initial Access (5), Command and Control (4).

- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 2 of 2 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1039](https://intel.threadlinqs.com/technique/T1039) Data from Network Shared Drive — Collection — observed in 2 of 2 tracked threats
- [T1047](https://intel.threadlinqs.com/technique/T1047) Windows Management Instrumentation — Execution — observed in 2 of 2 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 2 of 2 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 2 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 2 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 2 tracked threats
- [T1189](https://intel.threadlinqs.com/technique/T1189) Drive-by Compromise — Initial Access — observed in 2 of 2 tracked threats
- [T1484](https://intel.threadlinqs.com/technique/T1484) Domain or Tenant Policy Modification — Defense Impairment — observed in 2 of 2 tracked threats

## Tracked threats

- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — MEDIUM
- [Foxconn North American Factories Cyberattack — Nitrogen Ransomware Claims 8 TB / 11M+ Documents Stolen, Including Network Topologies for AMD/Intel/Google](https://intel.threadlinqs.com/threat/TL-2026-0511) — CRITICAL

## Related CVEs

6 CVEs referenced by tracked Nitrogen activity.

- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2020-0796](https://intel.threadlinqs.com/cve/CVE-2020-0796)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Nitrogen
