# Nitrogen Ransomware Coding Bug Permanently Destroys ESXi Data — Curve25519 Memory Corruption Makes Decryption Mathematically Impossible, Even Attackers Can't Decrypt, Azote Group UNC4696, Malvertising via Google/Bing Ads, Conti 2 Derivative

> Nitrogen ransomware ESXi variant contains a critical Curve25519 memory bug that overwrites 4 bytes of the master public key with zeros during encryption, making decryption mathematically impossible — even the threat actors cannot recover victim files. Derived from leaked Conti 2 builder code, the bug transforms ransomware into an accidental wiper. Operated by Azote Group (UNC4696), Nitrogen uses malvertising via Google/Bing ads for trojanized IT tools (WinSCP, PuTTY, KeePass) to deliver NitrogenLoader → Sliver/Cobalt Strike → BlackCat/ALPHV or standalone Nitrogen ransomware. Paying the ransom is mathematically pointless.

- **Published:** 2026-02-06T12:00:00Z
- **Last reviewed:** 2026-02-06T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0105
- **ID:** TL-2026-0105
- **Severity:** CRITICAL
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Azote Group
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Nitrogen ransomware's VMware ESXi variant contains a catastrophic cryptographic implementation bug discovered by Coveware (now Veeam) in February 2026. During file encryption using Curve25519 elliptic curve key exchange with ChaCha8 symmetric encryption, the malware stores the per-file public key as a stack variable at offset rsp+0x20. However, a subsequent QWORD (8-byte) write at rsp+0x1c overlaps and overwrites 4 bytes of the public key with zeros. This corrupted public key was never derived from any private key — it is a malformed value produced by unintended memory corruption. No corresponding private key exists in mathematical reality, making decryption fundamentally impossible by any party, including the threat actors themselves.

Nitrogen ransomware emerged from the leaked Conti 2 builder code and has been active since at least September 2024, operated by the Azote Group (tracked as UNC4696 by Mandiant). The group operates as both an Initial Access Broker and standalone ransomware operator. Initial access is gained through sophisticated malvertising campaigns on Google and Bing search engines, promoting trojanized versions of legitimate IT tools including WinSCP, Advanced IP Scanner, KeePass (via KeeLoader), PuTTY, and AnyDesk. Victims download ZIP/ISO bundles containing legitimate executables that sideload malicious Python DLLs (NitrogenLoader). The infection chain progresses through NitrogenInstaller (persistence via registry Run keys and scheduled tasks) → NitrogenStager (C2 establishment) → deployment of Sliver and Cobalt Strike beacons via Py-Fuscate obfuscated Python scripts → credential harvesting via LSASS dumps → lateral movement via Impacket wmiexec → data exfiltration via Restic → ransomware deployment.

The Windows variant encrypts files with .NBA extension and drops readme.txt ransom notes. The ESXi variant targets VMware hypervisors, where a single compromised host can impact dozens of critical VMs. The DFIR Report documented a complete intrusion where Time to Ransomware was 156 hours (8 days), culminating in BlackCat/ALPHV deployment via PsExec with Safe Mode boot for AV evasion. Nitrogen also exploits truesight.sys (a legitimate RogueKiller AntiRootkit driver listed in LOLDrivers) for BYOVD EDR/AV killing, and uses bcdedit.exe to disable Safe Boot recovery. The group shares code similarities with LukaLocker ransomware. Target sectors include finance, construction, manufacturing, technology, and nonprofits, primarily in the US, UK, Canada, Europe, and Africa. Notable victim: SRP Federal Credit Union (195,000+ customers, December 2024).

## MITRE ATT&CK

- T1583.001 Domains
- T1189 Drive-by Compromise
- T1059.006 Python
- T1059.001 PowerShell
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1078.002 Domain Accounts
- T1574.001 DLL
- T1685 Disable or Modify Tools
- T1027 Obfuscated Files or Information
- T1003.001 LSASS Memory
- T1018 Remote System Discovery
- T1087.002 Domain Account
- T1021.002 SMB/Windows Admin Shares
- T1570 Lateral Tool Transfer
- T1039 Data from Network Shared Drive
- T1071.001 Web Protocols
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1485 Data Destruction
- T1583.008 Malvertising
- T1047 Windows Management Instrumentation
- T1112 Modify Registry
- T1553.002 Code Signing
- T1021.006 Windows Remote Management
- T1074.001 Local Data Staging

## Sources

- [Coveware: Nitrogen Ransomware ESXi Malware Has a Bug](https://www.coveware.com/blog/2026/2/2/nitrogen-ransomware-esxi-malware-has-a-bug)
- [Veeam: Nitrogen Ransomware Bug](https://www.veeam.com/blog/nitrogen-ransomware-bug.html)
- [Bitdefender: Nitrogen Ransomware ESXi Bug Makes Decryption Impossible](https://www.bitdefender.com/en-us/blog/hotforsecurity/nitrogen-ransomware-esxi-bug-no-decryptor)
- [Tom's Hardware: Nitrogen Ransomware Key Management Bug](https://www.tomshardware.com/tech-industry/cyber-security/nitrogen-ransomware-programmers-lock-themselves-out-of-a-payment-key-management-bug-encrypts-victims-data-forever)
- [The DFIR Report: Nitrogen Campaign Drops Sliver and Ends With BlackCat](https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/)
- [CyberSecureFox: Nitrogen ESXi Bug — Irreversible Data Loss](https://cybersecurefox.com/en/nitrogen-ransomware-bug-vmware-esxi-data-loss/)
- [ANY.RUN: Nitrogen Ransomware Report](https://any.run/cybersecurity-blog/nitrogen-ransomware-report/)
- [CyberSecSentinel: Azote Group / UNC4696 Campaign Analysis](https://cybersecsentinel.com/threat-actor-azote-group-expands-nitrogen-ransomware-campaign-targeting-it-and-finance/)
- [BleepingComputer: Nitrogen Malware via Google Ads](https://www.bleepingcomputer.com/news/security/new-nitrogen-malware-pushed-via-google-ads-for-ransomware-attacks/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0105
