Skip to content
Prevention - centric cybersecurity
Complimentary POC
  • Prevention Services
    MANAGED NETWORK SECURITY
    • Palo Alto Networks Professional Service
    • SNPR – Secure Network Perimiter Response
    • Palo Alto Networks Professional Service
    • SNPR – Secure Network Perimiter Response
    MANAGED ENDPOINT SECURITY
    • MAED + EDR – Managed Endpoint Protection + Detection and Response
    • MAED + EDR – Managed Endpoint Protection + Detection and Response
    MANAGED CLOUD SECURITY
    • SCUD + CDR – Secure Cloud Unified Defense + Detection and Response
    • CMND – Cloud Managed Network Defense
    • SCUD + CDR – Secure Cloud Unified Defense + Detection and Response
    • CMND – Cloud Managed Network Defense
    24/7/365 SOC SERVICES
    • Threat Hunting
    • MVAP – Managed Vulnerability Assessment Platform
    • MXDR-Extended Detection and Response
    • Managed SOC & Incident Response
    • Threat Hunting
    • MVAP – Managed Vulnerability Assessment Platform
    • MXDR-Extended Detection and Response
    • Managed SOC & Incident Response
    All Services
    Prevention Services
  • Resources
    CONTENT
    • Blog
    • Threat Alert
    • Cybersecurity Glossary
    • Blog
    • Threat Alert
    • Cybersecurity Glossary
  • Company
    CONNECT WITH US
    • About Us
    • BLOKWORX Testimonials
    • Goodworx
    • Careers
    • About Us
    • BLOKWORX Testimonials
    • Goodworx
    • Careers
Complimentary POC

Threat Alert: Nitrogen

  • WHEN: Information Accurate as of 7/27/2023
  • WHO: This new malware appears to target those in the technology sector, like MSPs, based on the tools it attempts to appropriate
  • WHAT: Nitrogen installs a malicious version of software like  WinSCP (a tool utilized to connect to servers, such as Linux services with SSH enabled or file servers with FTP access).The ultimate goal is to drop ALPHV/BLackCat/Lockbit3.0 ransomware on the endpoint.
  • HOW DOES IT WORK? Malicious ads placed on Google/Facebook/Bing/etc. redirect to a very legitimate-looking site to download free software. As most people just click the first link of the software they want to download, this threat is easily propagated to victims.

    The package comes down as an ISO file including “Installer.exe” and msi.dll (malicious payload). The payload references a python path in the “Music” directory (out of the ordinary) and schedules a “OneDrive Security Task” handled by Python (also out of the ordinary).

    This payload deploys after the installation process and holds a strong foothold for the bad actors to move laterally through the network gaining access to key machines that they ransom.

  • HOW TO PREVENT: In order to avoid this threat, utilize a prevention first mindset and do not rely solely on detection. This campaign is not detected by many vendors and prevented by even fewer. The solution leveraged by BLOKWORX can and does prevent this threat, ensuring you stay safe from the “unknown” threats, like this. MAED Partners can rest assured, they are safe.
NO ONE SHOULD STAND ALONE AGAINST CYBER THREATS
ALL USA-BASED HUMANS READY TO SERVE YOU 24/7/365
CA • NV • CO • TX • OK • FL • VA • OR • NC

Contact

Phone: 775-200-9488
Email: Hello@blokworx.com
For Partner Support please email support@blokworx.com

Twitter Linkedin Youtube Facebook Instagram

Quick Links

  • Prevention Services
  • Testimonials
  • Threat Alert
  • Blog
  • Careers
  • Goodworx

BLOKWORX, LLC
10775 Double R Blvd.
Reno, NV 89521

 

 

Prevention - centric cybersecurity
Twitter Linkedin Youtube Facebook Instagram

© 2024 BLOKWORX • ALL RIGHTS RESERVED.