
An insidious malvertising campaign known as "Nitrogen" has been discovered, leveraging ads on Google Search and Bing to target users seeking IT tools such as AnyDesk, Cisco AnyConnect VPN, and WinSCP. This campaign aims to trick these users into downloading infected installers, aiming to breach enterprise networks for potential ransomware attacks.
According to an analysis released by cybersecurity firm Sophos on Wednesday, this "opportunistic" malvertising strategy has been found to deploy second-stage attack tools, including the infamous Cobalt Strike.
Nitrogen was first documented by the cybersecurity company eSentire in June 2023. The firm outlined an infection chain where users were redirected to compromised WordPress sites hosting malicious ISO image files. These files delivered Python scripts and Cobalt Strike Beacons onto the targeted system.
This month, another security firm, Trend Micro, revealed a similar attack sequence, where a fraudulent WinSCP application was used as a stepping stone to deploy BlackCat ransomware.
Throughout the infection chain, the threat actors employ uncommon export forwarding and DLL preloading techniques to mask their malicious activities and hinder analysis, reported Sophos researchers Gabor Szappanos, Morgan Demboski, and Benjamin Sollman. Once launched, the Python scripts establish a Meterpreter reverse TCP shell, allowing threat actors to remotely execute code on the infected host and download a Cobalt Strike Beacon to facilitate post-exploitation.
The researchers emphasized the growing trend of abusing pay-per-click advertisements in search engine results as a popular tactic among threat actors. They added that the threat actors cast a wide net to lure unsuspecting users seeking certain IT utilities.
This discovery comes amidst a worrying rise in cybercriminals using paid advertisements to trick users into downloading various malware strains such as BATLOADER, EugenLoader (aka FakeBat), and IcedID. These strains are then used to spread information stealers and other payloads.
In a concerning development, Sophos also discovered on major criminal marketplaces a significant number of advertisements and discussions about SEO poisoning, malvertising, and related services. Sellers were even found offering compromised Google Ads accounts. This highlights that users of these marketplaces have a keen interest in SEO poisoning and malvertising tactics. The researchers further pointed out that this method bypasses the challenges of email filters and convincing users to click a link or download and open an attachment.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543