216.73.217.22

New Nitrogen Ransomware Targets Financial Firms in the US, UK and Canada

· Published 20/05/2025 19:27 · Modified 21/05/2025 21:54

Export JSON

Essential information

Published
20/05/2025 19:27
Modified
21/05/2025 21:54
Tags
2025-05-20 cobalt strike data exfiltration malvertising meterpreter nitrogen ransomware vulnerable driver
Related entities
2 observables, 1 intrusion sets (apt), 10 techniques (mitre), 1 malware, 4 others

Description

, a new strain identified in September 2024, has become a significant threat to organizations worldwide, particularly in the financial sector. It encrypts critical data and demands substantial payments for decryption, targeting industries such as finance, construction, manufacturing, and technology in the United States, Canada, and the United Kingdom. The 's attack chain begins with campaigns on search engines, tricking users into downloading trojanized installers. It uses tools like and shells to establish persistence and move laterally within networks. Notable victims include SRP Federal Credit Union, Red Barrels, Control Panels USA, and Kilgore Industries. employs sophisticated tactics, including system reconnaissance, advanced evasion techniques, and exploitation of vulnerable drivers to disable security tools.

External references