Nymaim evolved from a ransomware-associated threat into a flexible malware downloader delivered primarily through phishing emails, including campaigns that abused a legitimate bulk email marketing service to improve delivery and evade blacklist-based defenses. Victims were lured into opening malicious Word documents or links to macro-enabled files, after which Nymaim installed and frequently fetched additional payloads such as the Ursnif banking Trojan; one observed infection chain dropped Pony first and then used it to retrieve Nymaim. Researchers also noted that the malware retained web-injection capabilities aimed at banking sessions and continued to use heavy in-memory obfuscation to complicate analysis and detection.
Later analysis showed Nymaim also overhauled its command-and-control resilience with a new wordlist-based domain generation algorithm (DGA) seeded by a hard-coded key and date values, producing domains across an 11-day sliding window with 64 domains per day alongside 46 hard-coded domains. The malware avoided exposing direct C2 addresses by transforming DNS A records into IPs, validating responses with a checksum mechanism, and screening NS records for sinkhole-related keywords before connecting. Once infrastructure was selected, the sample sent encrypted HTTP POST traffic to a hard-coded /index.php endpoint using AES and asymmetric encryption, underscoring Nymaim's transition into a more stealthy and resilient banking-malware delivery platform.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By 2014, researchers identified Nymaim-infected machines that also contained Vawtrak, Miuref, Pony, and Ursnif. This showed Nymaim functioning as a downloader capable of installing multiple malware families.
A new Nymaim version was observed in April 2018. The variant dropped most prior custom obfuscation, slightly changed its IP transformation constants, and completely rewrote its domain generation algorithm.
The analyzed Nymaim executable carried a compile timestamp of 2018-03-02 23:12:20. This sample was later examined as part of research into a substantially updated Nymaim variant.
In recent campaigns described by Proofpoint, threat actors used a legitimate bulk email marketing service to distribute Nymaim via malicious document attachments or links to macro-enabled documents. Proofpoint noted this marked a shift from Nymaim's more typical botnet-based spam distribution and improved delivery by leveraging trusted infrastructure.
On February 17, researchers tracked a malicious attachment campaign using Word documents with lures such as "February payment" and "Fedex Delivery Notification." The macros dropped Pony, which was then used to download Nymaim.
Nymaim was first observed in 2013. Early activity associated it with ransomware distribution before later campaigns emphasized its downloader role.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.