Ramnit is a banking trojan and file-infector malware family associated with banking fraud, credential theft, and follow-on malware delivery. The content describes Ramnit as targeting the banking sector and notes capabilities including information exfiltration, screenshot capture, and file execution. It is also referenced as a common information stealer and as malware that has used HVNC functionality for banking fraud. Multiple delivery chains are mentioned: sLoad is described as a PowerShell-based downloader primarily used to deliver the Ramnit banking trojan, including in a phishing campaign targeting users in Ukraine that used malicious RAR/ZIP archives and a disguised PDF LNK shortcut to launch PowerShell and stage additional payloads from Bitbucket and GitHub infrastructure. Ramnit was also observed being delivered by Bedep in malvertising-driven Angler exploit kit activity, and by AdGholas/Stegano exploit kit campaigns in which downloader/Kryptik samples either contained or downloaded Ramnit. The content further notes that, like Trickbot, Zloader, and Dridex, Ramnit operators were observed shifting away from pure banking fraud toward loader-style use for second-stage attacks, often ransomware. Sekoia.io also reported a significant increase in tracked Ramnit servers in 2023.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Ursnif has a multitude of modules for stealing email credentials, has a backdoor, keylogger, screenshot maker, and video maker... Ramnit is a file infector that has been targeting the banking sector as well, utilizing its many capabilities, such as information exfiltration, screenshot capture, file execution, etc.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan delivered by sLoad in this campaign.
Botnet-associated malware with observed command-and-control (C2) infrastructure activity tracked in 2023.
Referenced as a comparable banking trojan family that shifted toward acting as a loader for second-stage attacks, often ransomware.
A file-infector malware targeting the banking sector with capabilities including information exfiltration, screenshot capture, and file execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.