Ramnit is a long-running Windows malware family that originated around 2010 as a worm and file infector before evolving into a banking trojan with Zeus-derived functionality. It has been used to spy on infected users, steal banking and other credentials, inject malicious content into web sessions, harvest cookies, and download additional malware. Ramnit has also functioned as a loader for secondary payloads, including ransomware and proxy malware such as Ngioweb, and has been observed in broader criminal delivery ecosystems alongside loaders and downloaders such as sLoad and SnatchLoader.
Ramnit is notable for combining multiple capabilities in one family. Reported behaviors include credential theft, web injects against financial and payment-related sites, cookie theft, browser-focused hooking, hidden VNC-related functionality in the broader banking-malware ecosystem, custom command-and-control communications, and modular payload delivery. Some variants used a Domain Generation Algorithm for command-and-control discovery, while others relied on hardcoded infrastructure. Historical samples also exhibited file-infection behavior by appending malicious code to executable and HTML files, and some analyses described rootkit-like components, process injection, persistence mechanisms, and interference with security tooling.
Distribution has occurred through several common crimeware channels over time, including exploit kits, drive-by download campaigns, spam and malspam operations, and delivery by other malware families or loaders. Ramnit has been associated with campaigns using the RIG and Blackhole exploit kits, geographically filtered drive-by chains, and email-delivered downloader activity. It has also appeared as a follow-on payload in post-compromise activity and in malware service ecosystems linked to financially motivated actors.
Ramnit is primarily associated with financial cybercrime and online banking fraud, but its use has expanded beyond direct banking theft. It has targeted Windows users across multiple regions, with localized web-inject configurations and country-specific payloading observed in some campaigns. The family survived major disruption efforts, including a 2015 takedown, and remained active in later years. Reporting has also noted code or ecosystem relationships involving Bumblebee, Trickbot, and Conti-linked developers, although such links do not by themselves establish unified operations. Overall, Ramnit remains best characterized as a mature, adaptable Windows banking malware family with loader, theft, and post-compromise utility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Our Ramnit sample exploits both CVE-2013-3660 (by PlayBit) and CVE-2014-4113 (using the same exploit code originally found as a 0-Day). | CVE-2013-3660 ... Used by the following malware families: Dyre, Ramnit.
CVE-2013-3660 Classification: 1-Day Basic Description: Uninitialized kernel pointer in EPATHOBJ::pprFlattenRec Used by the following malware families: Dyre, Ramnit | CVE-2013-3660 ... Used by the following malware families: Dyre, Ramnit.
Appendix Microsoft Defender for Endpoint detection details Antivirus Microsoft Defender Antivirus detects exploitation behavior with these detections: ... Exploit:ASP/CVE-2021-27065 ... Defending against exploits and post-compromise activities Attackers exploit the on-premises Exchange Server vulnerabilities in combination to bypass authentication and gain the ability to write files and run malicious code.
Spelevo Exploit Kitは2つの脆弱性(CVE-2018-8174とCVE-2018-15982)を悪用することが報告されていますが、PseudoGateによる攻撃ではCVE-2018-15982のみが観測されています。CVE-2018-15982はAdobe Flash PlayerのRCEの脆弱性です。
In one notable example, the Lemon Duck operators compromised a system that already had xx.bat and a web shell. After establishing persistence on the system in a non-web shell method, the Lemon Duck operators were observed cleaning up other attackers’ presence on the system and mitigating the CVE-2021-26855 (SSRF) vulnerability using a legitimate cleanup script that they hosted on their own malicious server.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
sLoad is a PowerShell downloader that most frequently delivers Ramnit banker... Line 13: sLoad downloading Ramnit, after receiving a command to do so.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
First Seamless campaign which is a Drive-by Download attack campaign uses Ramnit banking trojan.
The user reads the landing page of the RIG Exploit Kit at Gate, which attacks and sends Ramnit.
Conclusion This post has been an overview of a downloader malware known as SnatchLoader... It is being delivered via spam campaigns
The emails are crafted in the targeted country’s language and are often personalized to include recipients’ names and addresses in various parts of the email such as email body and subject. TA554 frequently uses package delivery or order notification lures; the emails contain URLs linking to zipped LNK files or zipped documents.
The original exploit for CVE-2014-4113 was part of an exploit framework in which the API passes a command-line argument, and that command is executed as SYSTEM. As that wasn’t the original API for PlayBit’s exploit, some adjustments were made and PlayBit’s exploits were re-adjusted to receive a command-line argument to be executed once elevated.
Loader introduced with remote library injection ... Masquerades Bumblebee’s main DLL as a legitimate DLL
The second argument of “getexec” command is used to specify the file name for the downloaded executable... “msiexic.exe”
Loader introduced with remote library injection ... Masquerades Bumblebee’s main DLL as a legitimate DLL
PlayBit supplies the customer with a thin wrapper around the exploit, which checks whether the target computer is indeed vulnerable. Although the check varies a bit between different exploits and versions, the basics are the same: the modification date of the vulnerable win32k driver is checked, to detect if a patch was installed.
Dubbed ‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s legitimate login page and send the inputted information to the attacker.
This file seems to be zip. Looking inside it was IE's cookies. There was a DLL module that zipped the cookie, so it might be related.
Ramnit and Hupigon are both long-standing trojans that can facilitate data theft and the delivery of additional malware. Either could have been involved in the theft of credentials attackers later reused to access the housing authority’s system
malicious svchost.exe modifies or tries to modify every binary and HTML file by appending malicious code to each file or a vbs script to HTML files
PlayBit supplies the customer with a thin wrapper around the exploit, which checks whether the target computer is indeed vulnerable. Although the check varies a bit between different exploits and versions, the basics are the same: the modification date of the vulnerable win32k driver is checked, to detect if a patch was installed.
Dubbed ‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s legitimate login page and send the inputted information to the attacker.
Two malicious files communicate with it... It and a single housing authority IP address exchanged data 5,904 times between November 2 and December 30.
Ramnit uses the original protocol when communicating with C2. Following this protocol, I try to extract the configs and modules from the traffic of Ramnit and C2. This protocol uses port 443. But, not https.
Upon infection, the sample starts to make DNS queries for many different domains in rapid succession.
It is used mainly to turn the victim’s machine into malicious proxy servers... Ngioweb represents a multifunctional proxy server... The malware can operate in two main modes: Regular back-connect proxy Relay proxy.
The main functionality of SnatchLoader is to download and load additional malware families so most of the command types and arguments are in support of doing that in various ways
Upon infection, the sample starts to make DNS queries for many different domains in rapid succession.
203 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing and banking malware family delivered by SnatchLoader in the observed campaign.
Long-standing trojan associated here with credential theft, delivery of additional malware, and in some cases ransomware as a second-stage payload.
PC banking trojan listed among malware actively used to attack companies.
Mentioned only as a prior example of certutil-based decoding technique, not as part of this campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.