Threat reportRansomwareTL-2026-0105

Nitrogen Ransomware Coding Bug Permanently Destroys ESXi Data — Curve25519 Memory Corruption Makes Decryption Mathematically Impossible, Even Attackers Can't Decrypt, Azote Group UNC4696, Malvertising via Google/Bing Ads, Conti 2 Derivative

criticalACTIVE

Nitrogen Ransomware Coding Bug Permanently Destroys ESXi (TL-2026-0105) is a critical-severity ransomware operation, first published 2026-02-06. It is attributed to Azote Group with high confidence, maps to 27 MITRE ATT&CK techniques (T1003.001, T1018, T1021.002), and is covered by 9 detection rules and 35 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
27MITRE ATT&CK
Actors
2Azote Group
Detection rules
9SPL · KQL · Sigma
IOCs
35Indicators of compromise

Key facts for TL-2026-0105

Threat ID
TL-2026-0105
Severity
CRITICAL
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Azote Group, UNC4696
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
Finance, Construction, Manufacturing, Technology, Nonprofit, Government
Target regions
North America, Europe, United Kingdom, Africa
Detection rules
9
Indicators of compromise
35

Malware and tooling in Nitrogen Ransomware Coding Bug Permanently Destroys ESXi

Malware and tooling: nitrogen, Cobalt Strike, SLIVER

How Nitrogen Ransomware Coding Bug Permanently Destroys ESXi works

Nitrogen ransomware ESXi variant contains a critical Curve25519 memory bug that overwrites 4 bytes of the master public key with zeros during encryption, making decryption mathematically impossible — even the threat actors cannot recover victim files. Derived from leaked Conti 2 builder code, the bug transforms ransomware into an accidental wiper. Operated by Azote Group (UNC4696), Nitrogen uses malvertising via Google/Bing ads for trojanized IT tools (WinSCP, PuTTY, KeePass) to deliver NitrogenLoader → Sliver/Cobalt Strike → BlackCat/ALPHV or standalone Nitrogen ransomware. Paying the ransom is mathematically pointless.

Nitrogen ransomware's VMware ESXi variant contains a catastrophic cryptographic implementation bug discovered by Coveware (now Veeam) in February 2026. During file encryption using Curve25519 elliptic curve key exchange with ChaCha8 symmetric encryption, the malware stores the per-file public key as a stack variable at offset rsp+0x20. However, a subsequent QWORD (8-byte) write at rsp+0x1c overlaps and overwrites 4 bytes of the public key with zeros. This corrupted public key was never derived from any private key — it is a malformed value produced by unintended memory corruption. No corresponding private key exists in mathematical reality, making decryption fundamentally impossible by any party, including the threat actors themselves.

Nitrogen ransomware emerged from the leaked Conti 2 builder code and has been active since at least September 2024, operated by the Azote Group (tracked as UNC4696 by Mandiant). The group operates as both an Initial Access Broker and standalone ransomware operator. Initial access is gained through sophisticated malvertising campaigns on Google and Bing search engines, promoting trojanized versions of legitimate IT tools including WinSCP, Advanced IP Scanner, KeePass (via KeeLoader), PuTTY, and AnyDesk. Victims download ZIP/ISO bundles containing legitimate executables that sideload malicious Python DLLs (NitrogenLoader). The infection chain progresses through NitrogenInstaller (persistence via registry Run keys and scheduled tasks) → NitrogenStager (C2 establishment) → deployment of Sliver and Cobalt Strike beacons via Py-Fuscate obfuscated Python scripts → credential harvesting via LSASS dumps → lateral movement via Impacket wmiexec → data exfiltration via Restic → ransomware deployment.

The Windows variant encrypts files with .NBA extension and drops readme.txt ransom notes. The ESXi variant targets VMware hypervisors, where a single compromised host can impact dozens of critical VMs. The DFIR Report documented a complete intrusion where Time to Ransomware was 156 hours (8 days), culminating in BlackCat/ALPHV deployment via PsExec with Safe Mode boot for AV evasion. Nitrogen also exploits truesight.sys (a legitimate RogueKiller AntiRootkit driver listed in LOLDrivers) for BYOVD EDR/AV killing, and uses bcdedit.exe to disable Safe Boot recovery. The group shares code similarities with LukaLocker ransomware. Target sectors include finance, construction, manufacturing, technology, and nonprofits, primarily in the US, UK, Canada, Europe, and Africa. Notable victim: SRP Federal Credit Union (195,000+ customers, December 2024).

MITRE ATT&CK techniques used in TL-2026-0105

credential-access

T1003.001 LSASS Memory

discovery

T1018 Remote System Discovery; T1087.002 Domain Account

lateral-movement

T1021.002 SMB/Windows Admin Shares; T1021.006 Windows Remote Management; T1570 Lateral Tool Transfer

defense-evasion

T1027 Obfuscated Files or Information; T1078.002 Domain Accounts

collection

T1039 Data from Network Shared Drive; T1074.001 Local Data Staging

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1047 Windows Management Instrumentation; T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.006 Python

command-and-control

T1071.001 Web Protocols

defense-impairment

T1112 Modify Registry; T1553.002 Code Signing; T1685 Disable or Modify Tools

initial-access

T1189 Drive-by Compromise

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

persistence

T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL

resource-development

T1583.001 Domains; T1583.008 Malvertising

Remediation for Nitrogen Ransomware Coding Bug Permanently Destroys ESXi

Immediate actions

  • Verify ESXi backup integrity — Nitrogen-encrypted ESXi files are PERMANENTLY unrecoverable regardless of ransom payment
  • DO NOT PAY the ransom — decryption is mathematically impossible due to corrupted Curve25519 key pair
  • Isolate affected ESXi hosts immediately to prevent lateral spread
  • Block known Nitrogen C2 infrastructure at network edge (194.169.175.132, 194.180.48.169, 193.42.33.14, 141.98.6.195)
  • Block known malvertising domains: ftp-winscp.org, advanced-ip-scan.org, keeppaswrd.com, puttty.org

Workarounds

  • If encrypted by Nitrogen ESXi variant: analyze the specific malware sample used alongside encrypted files before any recovery attempt
  • Deploy EDR with vulnerable driver blocking (LOLDrivers detection)
  • Block Python runtime execution from non-standard paths

Longer-term hardening

  • Implement immutable/air-gapped backups for ESXi environments — offline backups are the ONLY recovery path against Nitrogen
  • Deploy ad-blocking or DNS filtering to prevent malvertising-based initial access
  • Restrict software downloads to official vendor sites only — enforce software allowlisting
  • Monitor for truesight.sys driver loading (BYOVD vector) and pythonw.exe from unusual paths
  • Implement ESXi Lockdown Mode and restrict management interface access
  • Test backup restoration procedures regularly — specifically for ESXi VM recovery

Weaknesses (CWE) in Nitrogen Ransomware Coding Bug Permanently Destroys ESXi

CWE-787

Timeline of Nitrogen Ransomware Coding Bug Permanently Destroys ESXi

  • Nitrogen initial access malware first reported by Sophos/BleepingComputer, using Google Ads malvertising to distribute trojanized IT tools. Source: https://www.bleepingcomputer.com/news/security/new-nitrogen-malware-pushed-via-google-ads-for-ransomware-attacks/
  • Earliest known Nitrogen ransomware sample dated September 2, 2024, identified via mutex nvxkjcv7yxctvgsdfjhv6esdvsx in ANY.RUN analysis. Source: https://any.run/cybersecurity-blog/nitrogen-ransomware-report/
  • The DFIR Report publishes comprehensive analysis of Nitrogen campaign leading to BlackCat/ALPHV ransomware deployment. 8-day intrusion via malvertising → DLL sideloading → Sliver/Cobalt Strike → credential harvesting → Restic exfiltration → ransomware. Source: https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/
  • Nitrogen group transitions from initial access broker selling to BlackCat/ALPHV affiliates to operating standalone ransomware with .NBA extension and readme.txt ransom notes.
  • SRP Federal Credit Union (South Carolina, 195,000+ customers) confirmed as Nitrogen ransomware victim. Source: https://any.run/cybersecurity-blog/nitrogen-ransomware-report/
  • Nextron Systems publishes analysis of Nitrogen dropping Cobalt Strike with detailed IOC analysis. Source: https://www.nextron-systems.com/2025/04/29/nitrogen-dropping-cobalt-strike-a-combination-of-chemical-elements/
  • Azote Group / UNC4696 attribution established. Campaign expanded to target IT, finance, manufacturing, construction, and nonprofit sectors across US, UK, Canada, Europe, and Africa. Source: https://cybersecsentinel.com/threat-actor-azote-group-expands-nitrogen-ransomware-campaign-targeting-it-and-finance/
  • Early reporting of Nitrogen ESXi encryption bug surfaces. Veeam/Coveware analysis of the Curve25519 memory corruption flaw completed. Source: https://www.thenasguy.com/2026/01/30/esxi-ransomware-bug-paying-wont-restore-your-files/
  • Coveware (now Veeam) publishes detailed reverse engineering of Nitrogen ESXi cryptographic bug. The malware overwrites 4 bytes of the Curve25519 public key at rsp+0x20 due to overlapping QWORD write at rsp+0x1c, making decryption permanently impossible. Source: https://www.coveware.com/blog/2026/2/2/nitrogen-ransomware-esxi-malware-has-a-bug
  • Original threat creation date preserved for Threadlinqs Intelligence database entry.
  • As of 2026-05-29, Nitrogen ransomware (Azote Group/UNC4696) remains ACTIVE: it claimed the ~8TB Foxconn breach on 11 May 2026 (confirmed by Foxconn 12 May), and its NitroBlog leak site is live with 47 victims per ransomware.live. No CVE/KEV applies, no takedown or arrests reported; the self-inflicted Curve25519 ESXi bug still makes decryption impossible, worsening victim impact.

Sources cited for Nitrogen Ransomware Coding Bug Permanently Destroys ESXi

Detection coverage for TL-2026-0105

As of 2026-02-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0105 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
35 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats