Nitrogen is a financially motivated ransomware and double-extortion operation documented by mid-2024. SECUINFRA assessed that the Nitrogen and LukaLocker ransomware variants were likely created and deployed by the same threat actor, but it found no established connection between Nitrogen ransomware and the separate malware called Nitrogen Loader. Halcyon later assessed continuity from an earlier loader operation; because the sources differ, this profile treats mid-2024 ransomware activity as the supported boundary rather than presenting a 2023 lineage as confirmed.
Activity and targeting
SECUINFRA’s observed sample and leak-site set was concentrated in the United States and Canada, particularly industrial and construction organizations, with occasional victims in other sectors suggesting opportunistic selection. Halcyon reported a renewed 2026 campaign in which NitroBlog listed multiple manufacturing organizations, including electronics and supply-chain targets. Leak-site listings and claimed data volumes remain actor assertions unless independently corroborated.
The operation uses public victim naming and alleged-data previews to create payment pressure. SECUINFRA observed the operators offering allegedly stolen data to other criminals rather than publishing every dataset in full. Halcyon’s 2026 reporting describes the same NitroBlog brand and a broader focus spanning construction, financial services, manufacturing and technology.
Methods and operational characteristics
SECUINFRA found that Nitrogen’s Windows ransomware implementation largely reused leaked Conti source code, with ChaCha8 file encryption and Curve25519 protection of per-file keys. The analyzed tooling supported process and service handling, multithreaded encryption, configurable target paths and forced restart behavior. The operation communicated through unique Tox identifiers in ransom notes and used a Tor-hosted leak blog.
Halcyon reported 2026 initial-access activity involving malvertising and trojanized installers for legitimate administration or network utilities. It also warned that a reported memory-management defect in Nitrogen’s VMware ESXi encryptor could corrupt the public key and make decryption impossible even after payment. These behaviors come from particular observed or reported campaigns and should not be assumed in every Nitrogen intrusion.
What type of group is it?
Nitrogen is best characterized as a financially motivated ransomware group conducting encryption and data-theft extortion. Public evidence does not identify its operators, jurisdiction or organizational structure, and it does not support state direction. The likely LukaLocker relationship is based on malware similarity and victim or leak-site correlation, not identified common operators. The conflicting assessments about Nitrogen Loader also make clear that name overlap is not sufficient proof of identity.