Nymaim is a Windows malware family first documented in 2013. Initially observed as a first-stage downloader and ransomware-style screen locker, it evolved into a modular downloader used to install additional malware, notably banking trojans and ransomware. Documented secondary payloads include Ursnif and other commodity malware.
Nymaim has been delivered through exploit-kit drive-by activity and malicious email campaigns using macro-enabled Office documents or links to such documents. It has also been distributed by malware delivery services including Emotet and PrivateLoader, and has appeared as a follow-on payload in Gozi ISFB infection chains.
The malware uses extensive obfuscation, encrypted configuration data interpreted by an embedded custom virtual machine, anti-debugging, virtual-machine and sandbox checks, and antivirus-process detection. It profiles compromised systems and has incorporated information-stealing functionality. Historical variants used web injections to monitor banking-site visits and alter banking-page content to facilitate fraudulent transactions. Nymaim also uses domain-generation mechanisms and encrypted command-and-control communications. Its operators and ownership model have not been conclusively identified, although technical research has identified strong development links with the Xpaj malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This threat actor typically targets Canada with false shipping lures, such as CanadaPost and DHL, and have attempted to deliver Ursnif, DanaBot, and Nymaim in the past.
Poland (Defunct) Polish Nymaim Medium Volume Manufacturing Campaigns began regularly in March of 2017 and appear to have gone on hiatus in May of 2018.
Previous distribution activity associated with Storm-0324 included the Gozi infostealer and the Nymaim downloader and locker.
"Malicious Microsoft Office Document using encoded macros ... also seen for Nymaim ransomware delivery"
27 distinct techniques documented for this family, organized by ATT&CK tactic.
At that time, Nymaim was largely distributed via the Black Hole Exploit Kit (BHEK) as a "drive-by download."
In 2016, we documented distribution of the Ursnif banking Trojan via email campaigns
Nymaim ... is well known for using an advanced custom obfuscation engine, which makes it very difficult to analyse the code ... the way in which the code is written and obfuscated.
the custom "ARCH" structure known to be used by Nymaim in order to keep the aplib32 compressed data is also used by Xpaj
SignalEvent(); // pre-process termination ... Exit(0); // Exit process
Detecting sandboxing and debugging environment (IsDebugged())
The virtual machine uses IsDebugged() for anti-debugging checks, looking for blacklisted items associated with research environments: MAC addresses associated with virtual machine platform vendors VmWare, Dell, PCS Computer Systems GmbH, Microsoft Corporation, Parallels, and Xensource.
the config interpreter can communicate with other parts of the Nymaim code using a structure holding initial data, which includes: IsAdmin flag; System version from a OSVERSIONINFOEXW structure; SubAuthID; Locale obtained by GetLocaleInfoA; Pointer to the PEB
Detecting sandboxing and debugging environment (IsDebugged())
The virtual machine uses IsDebugged() for anti-debugging checks, looking for blacklisted items associated with research environments: MAC addresses associated with virtual machine platform vendors VmWare, Dell, PCS Computer Systems GmbH, Microsoft Corporation, Parallels, and Xensource.
we have discovered interesting similarities in ... the communication protocol
This screenshot shows traffic generated by the malware to its injection control IP address 31.184.234[.]21. The malware reports that the user is visiting a banking site. It then receives instructions on how to modify and replace content to initiate fraud on the user’s account.
Nymaim on its own is a dropper. It acts solely as a gateway—a delivery system for other strands of malware. GozNym uses Nymaim’s advanced stealth capabilities to unload the previously mentioned Gozi malware.
A distinctive feature of Nymaim is the DNS query for the name server record (NS). Nymaim checks if any of the answers contains a word from a list it calls BlackNsWords... If Nymaim finds any of those word in the NS resource record, it will not use the domain.
225 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Nymaim is mentioned only as an earlier example of malware using API hammering.
Nymaim is a heavily obfuscated malware family that evolved from a dropper into a banking-capable threat. It distributes payloads, performs web injects, uses DGA and P2P communications, fingerprints infected hosts, downloads additional binaries, and can act through dropper, payload, and bot_peer modules.
Nymaim variant observed as a payload delivered by PrivateLoader.
Nymaim is a trojan historically associated with banking fraud activity, including credential theft and web-injection style techniques, and has also been used as a loader for additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.