Threat reportRansomwareTL-2026-0105
Nitrogen Ransomware Coding Bug Permanently Destroys ESXi Data — Curve25519 Memory Corruption Makes Decryption Mathematically Impossible, Even Attackers Can't Decrypt, Azote Group UNC4696, Malvertising via Google/Bing Ads, Conti 2 Derivative
Nitrogen Ransomware Coding Bug Permanently Destroys ESXi (TL-2026-0105) is a critical-severity ransomware operation, first published 2026-02-06. It is attributed to Azote Group with high confidence, maps to 27 MITRE ATT&CK techniques (T1003.001, T1018, T1021.002), and is covered by 9 detection rules and 35 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 27MITRE ATT&CK
- Actors
- 2Azote Group
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-0105
- Threat ID
- TL-2026-0105
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Azote Group, UNC4696
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- Finance, Construction, Manufacturing, Technology, Nonprofit, Government
- Target regions
- North America, Europe, United Kingdom, Africa
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in Nitrogen Ransomware Coding Bug Permanently Destroys ESXi
Malware and tooling: nitrogen, Cobalt Strike, SLIVER
How Nitrogen Ransomware Coding Bug Permanently Destroys ESXi works
Nitrogen ransomware ESXi variant contains a critical Curve25519 memory bug that overwrites 4 bytes of the master public key with zeros during encryption, making decryption mathematically impossible — even the threat actors cannot recover victim files. Derived from leaked Conti 2 builder code, the bug transforms ransomware into an accidental wiper. Operated by Azote Group (UNC4696), Nitrogen uses malvertising via Google/Bing ads for trojanized IT tools (WinSCP, PuTTY, KeePass) to deliver NitrogenLoader → Sliver/Cobalt Strike → BlackCat/ALPHV or standalone Nitrogen ransomware. Paying the ransom is mathematically pointless.
Nitrogen ransomware's VMware ESXi variant contains a catastrophic cryptographic implementation bug discovered by Coveware (now Veeam) in February 2026. During file encryption using Curve25519 elliptic curve key exchange with ChaCha8 symmetric encryption, the malware stores the per-file public key as a stack variable at offset rsp+0x20. However, a subsequent QWORD (8-byte) write at rsp+0x1c overlaps and overwrites 4 bytes of the public key with zeros. This corrupted public key was never derived from any private key — it is a malformed value produced by unintended memory corruption. No corresponding private key exists in mathematical reality, making decryption fundamentally impossible by any party, including the threat actors themselves.
Nitrogen ransomware emerged from the leaked Conti 2 builder code and has been active since at least September 2024, operated by the Azote Group (tracked as UNC4696 by Mandiant). The group operates as both an Initial Access Broker and standalone ransomware operator. Initial access is gained through sophisticated malvertising campaigns on Google and Bing search engines, promoting trojanized versions of legitimate IT tools including WinSCP, Advanced IP Scanner, KeePass (via KeeLoader), PuTTY, and AnyDesk. Victims download ZIP/ISO bundles containing legitimate executables that sideload malicious Python DLLs (NitrogenLoader). The infection chain progresses through NitrogenInstaller (persistence via registry Run keys and scheduled tasks) → NitrogenStager (C2 establishment) → deployment of Sliver and Cobalt Strike beacons via Py-Fuscate obfuscated Python scripts → credential harvesting via LSASS dumps → lateral movement via Impacket wmiexec → data exfiltration via Restic → ransomware deployment.
The Windows variant encrypts files with .NBA extension and drops readme.txt ransom notes. The ESXi variant targets VMware hypervisors, where a single compromised host can impact dozens of critical VMs. The DFIR Report documented a complete intrusion where Time to Ransomware was 156 hours (8 days), culminating in BlackCat/ALPHV deployment via PsExec with Safe Mode boot for AV evasion. Nitrogen also exploits truesight.sys (a legitimate RogueKiller AntiRootkit driver listed in LOLDrivers) for BYOVD EDR/AV killing, and uses bcdedit.exe to disable Safe Boot recovery. The group shares code similarities with LukaLocker ransomware. Target sectors include finance, construction, manufacturing, technology, and nonprofits, primarily in the US, UK, Canada, Europe, and Africa. Notable victim: SRP Federal Credit Union (195,000+ customers, December 2024).
MITRE ATT&CK techniques used in TL-2026-0105
credential-access
discovery
T1018 Remote System Discovery; T1087.002 Domain Account
lateral-movement
T1021.002 SMB/Windows Admin Shares; T1021.006 Windows Remote Management; T1570 Lateral Tool Transfer
defense-evasion
T1027 Obfuscated Files or Information; T1078.002 Domain Accounts
collection
T1039 Data from Network Shared Drive; T1074.001 Local Data Staging
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1047 Windows Management Instrumentation; T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.006 Python
command-and-control
defense-impairment
T1112 Modify Registry; T1553.002 Code Signing; T1685 Disable or Modify Tools
initial-access
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
persistence
T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL
resource-development
Remediation for Nitrogen Ransomware Coding Bug Permanently Destroys ESXi
Immediate actions
- Verify ESXi backup integrity — Nitrogen-encrypted ESXi files are PERMANENTLY unrecoverable regardless of ransom payment
- DO NOT PAY the ransom — decryption is mathematically impossible due to corrupted Curve25519 key pair
- Isolate affected ESXi hosts immediately to prevent lateral spread
- Block known Nitrogen C2 infrastructure at network edge (194.169.175.132, 194.180.48.169, 193.42.33.14, 141.98.6.195)
- Block known malvertising domains: ftp-winscp.org, advanced-ip-scan.org, keeppaswrd.com, puttty.org
Workarounds
- If encrypted by Nitrogen ESXi variant: analyze the specific malware sample used alongside encrypted files before any recovery attempt
- Deploy EDR with vulnerable driver blocking (LOLDrivers detection)
- Block Python runtime execution from non-standard paths
Longer-term hardening
- Implement immutable/air-gapped backups for ESXi environments — offline backups are the ONLY recovery path against Nitrogen
- Deploy ad-blocking or DNS filtering to prevent malvertising-based initial access
- Restrict software downloads to official vendor sites only — enforce software allowlisting
- Monitor for truesight.sys driver loading (BYOVD vector) and pythonw.exe from unusual paths
- Implement ESXi Lockdown Mode and restrict management interface access
- Test backup restoration procedures regularly — specifically for ESXi VM recovery
Weaknesses (CWE) in Nitrogen Ransomware Coding Bug Permanently Destroys ESXi
Timeline of Nitrogen Ransomware Coding Bug Permanently Destroys ESXi
- Nitrogen initial access malware first reported by Sophos/BleepingComputer, using Google Ads malvertising to distribute trojanized IT tools. Source: https://www.bleepingcomputer.com/news/security/new-nitrogen-malware-pushed-via-google-ads-for-ransomware-attacks/
- Earliest known Nitrogen ransomware sample dated September 2, 2024, identified via mutex nvxkjcv7yxctvgsdfjhv6esdvsx in ANY.RUN analysis. Source: https://any.run/cybersecurity-blog/nitrogen-ransomware-report/
- The DFIR Report publishes comprehensive analysis of Nitrogen campaign leading to BlackCat/ALPHV ransomware deployment. 8-day intrusion via malvertising → DLL sideloading → Sliver/Cobalt Strike → credential harvesting → Restic exfiltration → ransomware. Source: https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/
- Nitrogen group transitions from initial access broker selling to BlackCat/ALPHV affiliates to operating standalone ransomware with .NBA extension and readme.txt ransom notes.
- SRP Federal Credit Union (South Carolina, 195,000+ customers) confirmed as Nitrogen ransomware victim. Source: https://any.run/cybersecurity-blog/nitrogen-ransomware-report/
- Nextron Systems publishes analysis of Nitrogen dropping Cobalt Strike with detailed IOC analysis. Source: https://www.nextron-systems.com/2025/04/29/nitrogen-dropping-cobalt-strike-a-combination-of-chemical-elements/
- Azote Group / UNC4696 attribution established. Campaign expanded to target IT, finance, manufacturing, construction, and nonprofit sectors across US, UK, Canada, Europe, and Africa. Source: https://cybersecsentinel.com/threat-actor-azote-group-expands-nitrogen-ransomware-campaign-targeting-it-and-finance/
- Early reporting of Nitrogen ESXi encryption bug surfaces. Veeam/Coveware analysis of the Curve25519 memory corruption flaw completed. Source: https://www.thenasguy.com/2026/01/30/esxi-ransomware-bug-paying-wont-restore-your-files/
- Coveware (now Veeam) publishes detailed reverse engineering of Nitrogen ESXi cryptographic bug. The malware overwrites 4 bytes of the Curve25519 public key at rsp+0x20 due to overlapping QWORD write at rsp+0x1c, making decryption permanently impossible. Source: https://www.coveware.com/blog/2026/2/2/nitrogen-ransomware-esxi-malware-has-a-bug
- Original threat creation date preserved for Threadlinqs Intelligence database entry.
- As of 2026-05-29, Nitrogen ransomware (Azote Group/UNC4696) remains ACTIVE: it claimed the ~8TB Foxconn breach on 11 May 2026 (confirmed by Foxconn 12 May), and its NitroBlog leak site is live with 47 victims per ransomware.live. No CVE/KEV applies, no takedown or arrests reported; the self-inflicted Curve25519 ESXi bug still makes decryption impossible, worsening victim impact.
Sources cited for Nitrogen Ransomware Coding Bug Permanently Destroys ESXi
- Coveware: Nitrogen Ransomware ESXi Malware Has a Bug
- Veeam: Nitrogen Ransomware Bug
- Bitdefender: Nitrogen Ransomware ESXi Bug Makes Decryption Impossible
- Tom's Hardware: Nitrogen Ransomware Key Management Bug
- The DFIR Report: Nitrogen Campaign Drops Sliver and Ends With BlackCat
- CyberSecureFox: Nitrogen ESXi Bug — Irreversible Data Loss
- ANY.RUN: Nitrogen Ransomware Report
- CyberSecSentinel: Azote Group / UNC4696 Campaign Analysis
- BleepingComputer: Nitrogen Malware via Google Ads
Detection coverage for TL-2026-0105
As of 2026-02-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0105 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.