Researchers documented Trojan.Win32/Spy.Ranbyus, a malware family tied to financial theft and online banking fraud, describing capabilities that included process injection, persistence through registry changes, anti-security checks, and theft of files, screenshots, commands, smartcard-related data, and banking credentials. Analysis also linked the malware to Russian banking targets, WebMoney activity, Java modification, and smartcard-enabled bot operations, while showing infrastructure used to push additional malware components and a botnet control panel associated with the campaign.
A separate analysis showed Ranbyus being distributed through phishing emails that falsely warned users their Facebook account had been blocked or closed, luring them into opening a ZIP attachment containing an executable downloader. After launch, the malware displayed a fake reassurance message, installed itself under randomized names, kept two processes watching each other for resilience, and used heavy obfuscation and anti-debugging tricks before generating time-based .net domains through a domain-generation algorithm to fetch and run follow-on payloads from %TEMP%, extending the infection chain beyond the initial lure.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
On 2013-06-18, Avast published an analysis of a phishing campaign using fake Facebook account closure or blocking emails with ZIP attachments carrying a downloader executable. The analysis detailed the malware's obfuscation, dual watchdog processes, domain-generation algorithm, and payload download-and-execute behavior.
On 2013-01-27, XyliBox published reverse-engineering details on Trojan.Win32/Spy.Ranbyus, describing its banking-focused theft capabilities, persistence mechanisms, anti-security checks, and botnet control panel features. The post also linked the malware to a Russian carding group that allegedly called it "triton" and listed payload distribution URLs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 60 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.