W32.Ramnit is malware described in the provided content as a worm and remote access tool that debuted in 2010. It provides attackers with remote access to infected systems, steals files, and can inject code into webpages to capture banking data, indicating use in credential and financial-data theft. The content also states that it can spread through USB sticks/removable drives. In the cited incident at Germany’s Gundremmingen nuclear power plant, W32.Ramnit was found alongside Conficker on a computer system associated with fuel rod handling or modelling and on multiple USB removable storage devices. RWE reported that the affected systems were isolated from the Internet, which prevented the malware from activating, updating, contacting command-and-control infrastructure, or stealing data, and the incident was assessed as causing no operational harm. Based on the content, the malware in this case did not appear to reflect targeted industrial sabotage; it was characterized as common malware more consistent with financial fraud-oriented activity than disruption of industrial processes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access tool used by its operators to steal data.
Malware that steals files from computers and can spread through USB sticks.
A worm that provides remote access, steals files, and injects code into webpages to capture banking data. It also spreads through USB drives and depends on Internet connectivity for command-and-control communication.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.