Nymaim is a long-running Windows malware family first documented in 2013. It initially gained notoriety as a ransomware-style screen locker combined with downloader functionality, but later evolved into a heavily obfuscated downloader and malware delivery platform. Over time it has been used to install additional payloads including banking trojans and ransomware, and some variants also incorporated information-stealing, system-profiling, and web-injection capabilities.
Nymaim has been associated with multiple criminal delivery ecosystems and malware chains. It has been observed in campaigns distributing or delivering Ursnif and other banking malware, and it has also appeared in infection chains involving Emotet, Gozi ISFB, Pony, and PrivateLoader. The GozNym banking malware combined Gozi functionality with the Nymaim dropper component. Reporting has also identified technical overlaps between Nymaim and the older Xpaj malware family, suggesting shared development lineage.
Delivery has varied across campaigns. Early activity was linked to exploit-kit-driven drive-by compromise, particularly via Blackhole. Later campaigns relied heavily on malicious spam and phishing emails carrying weaponized Office documents or links to macro-enabled documents. In some operations, attackers abused legitimate bulk email marketing services to improve deliverability and evade reputation-based filtering. Nymaim has also been observed as a payload distributed by other malware loaders and botnets, including Emotet and PrivateLoader.
Functionally, Nymaim is best characterized as a downloader that executes follow-on malware on infected systems. In addition to payload delivery, documented variants performed browser-session monitoring and web injection against banking sites, enabling fraudulent transaction manipulation. More recent analysis also showed information-stealing and host-profiling logic, along with extensive anti-analysis and defense-evasion measures. Nymaim uses strong obfuscation, custom deobfuscation patterns, encrypted configuration data, and in some versions a custom virtual machine to interpret compiled configuration bytecode. Anti-debugging and anti-sandbox checks have included inspection of running security tools, virtualization artifacts, suspicious usernames or hostnames, and debugging-related libraries.
Nymaim also employed resilient command-and-control techniques. Researchers documented domain-generation algorithms in multiple versions, including later wordlist-based DGA logic, as well as DNS-based filtering intended to avoid sinkholes. Some variants transformed DNS response data before using it for command-and-control and protected communications with encrypted request formats.
Victimology has been broad and international, with campaigns observed globally and specific targeting noted in North America and parts of Europe including Germany, Italy, and Poland. Banking-related functionality and web injects indicate a strong historical focus on financial fraud, though Nymaim has also served as a general-purpose malware gateway for broader cybercriminal operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This threat actor typically targets Canada with false shipping lures, such as CanadaPost and DHL, and have attempted to deliver Ursnif, DanaBot, and Nymaim in the past.
Poland (Defunct) Polish Nymaim Medium Volume Manufacturing Campaigns began regularly in March of 2017 and appear to have gone on hiatus in May of 2018.
Previous distribution activity associated with Storm-0324 included the Gozi infostealer and the Nymaim downloader and locker.
"Malicious Microsoft Office Document using encoded macros ... also seen for Nymaim ransomware delivery"
27 distinct techniques documented for this family, organized by ATT&CK tactic.
At that time, Nymaim was largely distributed via the Black Hole Exploit Kit (BHEK) as a "drive-by download."
In 2016, we documented distribution of the Ursnif banking Trojan via email campaigns
Nymaim ... is well known for using an advanced custom obfuscation engine, which makes it very difficult to analyse the code ... the way in which the code is written and obfuscated.
the custom "ARCH" structure known to be used by Nymaim in order to keep the aplib32 compressed data is also used by Xpaj
SignalEvent(); // pre-process termination ... Exit(0); // Exit process
Detecting sandboxing and debugging environment (IsDebugged())
The virtual machine uses IsDebugged() for anti-debugging checks, looking for blacklisted items associated with research environments: MAC addresses associated with virtual machine platform vendors VmWare, Dell, PCS Computer Systems GmbH, Microsoft Corporation, Parallels, and Xensource.
the config interpreter can communicate with other parts of the Nymaim code using a structure holding initial data, which includes: IsAdmin flag; System version from a OSVERSIONINFOEXW structure; SubAuthID; Locale obtained by GetLocaleInfoA; Pointer to the PEB
Detecting sandboxing and debugging environment (IsDebugged())
The virtual machine uses IsDebugged() for anti-debugging checks, looking for blacklisted items associated with research environments: MAC addresses associated with virtual machine platform vendors VmWare, Dell, PCS Computer Systems GmbH, Microsoft Corporation, Parallels, and Xensource.
we have discovered interesting similarities in ... the communication protocol
This screenshot shows traffic generated by the malware to its injection control IP address 31.184.234[.]21. The malware reports that the user is visiting a banking site. It then receives instructions on how to modify and replace content to initiate fraud on the user’s account.
Nymaim on its own is a dropper. It acts solely as a gateway—a delivery system for other strands of malware. GozNym uses Nymaim’s advanced stealth capabilities to unload the previously mentioned Gozi malware.
A distinctive feature of Nymaim is the DNS query for the name server record (NS). Nymaim checks if any of the answers contains a word from a list it calls BlackNsWords... If Nymaim finds any of those word in the NS resource record, it will not use the domain.
225 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Nymaim is mentioned only as an earlier example of malware using API hammering.
Nymaim is a heavily obfuscated malware family that evolved from a dropper into a banking-capable threat. It distributes payloads, performs web injects, uses DGA and P2P communications, fingerprints infected hosts, downloads additional binaries, and can act through dropper, payload, and bot_peer modules.
Nymaim variant observed as a payload delivered by PrivateLoader.
Nymaim is a trojan historically associated with banking fraud activity, including credential theft and web-injection style techniques, and has also been used as a loader for additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.