Clampi is a Windows man-in-the-browser banking trojan, also known as Ligats, Ilomo, and Rscan, first observed in 2007. It was designed to steal financial and personal information from compromised systems for financial gain, report host configuration data, communicate with central command-and-control infrastructure, and download additional malware. The malware monitored more than 4,000 targeted URLs, with researchers identifying around 4,800 CRC-encoded URLs, and targeted not only banking and credit card sites but also utility, market research, online casino, and career websites. Reported capabilities include logging and transmitting personal financial information, stealing PSTORE passwords from Internet Explorer, stealing locally saved credentials from applications such as instant messaging and FTP clients, capturing credentials when victims visited targeted URLs, and using an extended logging component to steal credentials from enhanced-security sites including HTTPS. Clampi could also establish a SOCKS proxy on infected hosts, allowing attackers to access victim bank accounts through the victim’s own internet connection, spread to other systems via shared network directories, and collect general system information. Analysis by Nicolas Falliere found Clampi unusually difficult to reverse engineer because it used the VMProtect virtual machine to hide its instruction set, reportedly the first trojan observed doing so, adding weeks to analysis effort. It was also reported to exploit Internet Explorer 8 and to evade firewalls and remain undetected for long periods. At its peak in fall 2009, Clampi was described as one of the largest and most professional online credential-theft operations, and the operation was assessed as likely run by a Russian or Eastern European criminal syndicate.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Clampi monitored over 4000 website URLs, effectively keylogging credentials and user information for not only bank and credit card websites
He discovered it logged and transmitted personal financial information from a compromised computer to a third party ... communicated with a central server
He discovered it logged and transmitted personal financial information from a compromised computer to a third party ... as well as reported on computer configuration, communicated with a central server
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows banking trojan and man-in-the-browser malware family that steals financial and personal information, logs credentials, reports system configuration, communicates with a central server, sets up a SOCKS proxy, spreads via shared directories, and can download additional malware.
A Windows banking trojan and man-in-the-browser malware family that steals financial and personal information, keylogs credentials, reports system configuration, communicates with a central server, sets up a SOCKS proxy, spreads via shared directories, steals saved credentials from applications, and can download additional malware.
2007 Alureon BlackEnergy Clampi Mebroot Storm ZeuS
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.