Ramsay is a Windows malware framework associated with espionage operations against air-gapped or otherwise isolated networks. It is designed to collect documents and system information from compromised hosts and to move commands and stolen data through offline channels rather than relying primarily on conventional network command-and-control. Public reporting has linked Ramsay to operations attributed to DarkHotel.
Ramsay has been delivered through malicious email attachments and weaponized documents, including embedded Visual Basic script content and exploits such as CVE-2017-0199 and CVE-2017-11882. It has also masqueraded as legitimate software installers. The framework can extract an embedded agent from a malicious document and execute additional components through standard Windows process-launching APIs.
A defining characteristic of Ramsay is its focus on environments with limited or no internet connectivity. It can scan removable media and network shares for specially prepared files used as an offline control channel, then read instructions from those files to execute commands. Its documented offline protocol supports actions including executing files, loading DLLs, and running batch scripts. Ramsay also scans local subnets for hosts vulnerable to CVE-2017-0144, although no observed component has been shown exploiting that vulnerability directly.
On infected Windows systems, Ramsay performs host and network reconnaissance by enumerating running processes and collecting network configuration details using native utilities and APIs. It can gather routing and ARP information, identify network drives, and search for documents of intelligence value. Document collection has included Microsoft Word files and other common office and text formats, including files recovered from browser cache locations. Ramsay also supports screenshot capture at regular intervals and when removable storage is connected, reinforcing its surveillance role in disconnected environments.
For persistence and stealth, Ramsay has used scheduled tasks through the Windows COM API, Registry Run keys, and DLL side-loading or dependency hijacking with malicious DLL payloads. It has also been observed using reflective DLL injection to deploy components and UACMe to obtain elevated privileges. Its communications and data handling have included Base64 encoding for command-and-control traffic in connected scenarios. Overall, Ramsay is best characterized as an espionage-oriented collection platform tailored for Windows systems in segmented or air-gapped networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Ramsay used a much more aggressive approach by automatically scanning all IP addresses in the local subnet and testing the discovered hosts to determine whether they are vulnerable to CVE-2017-0144, also known as EternalBlue. Note that we have not seen any Ramsay component capable of exploiting the vulnerability. | Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks ... Ramsay’s primary collection target is Microsoft Word documents ...
Ramsay ... Malicious RTF documents exploiting CVE-2017-0199 (Office/WordPad RCE), CVE-2017-11882 (Office RCE). | Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks ... Ramsay’s primary collection target is Microsoft Word documents ...
USBCulprit ... exploiting one days (CVE-2012-0158, CVE-2017-11882, CVE-2018-0802)... Retro ... Spearphishing with documents that exploit CVE-2017-11882. ... Ramsay ... Malicious RTF documents exploiting ... CVE-2017-11882 (Office RCE). | Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks ... Ramsay’s primary collection target is Microsoft Word documents ...
Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
安全厂商ESET 近日又披露了该组织新恶意框架Ramsay,Ramsay 框架是疑似专门用于针对隔离网络的恶意代码,主要通过感染正常软件进行传播,同时与常规恶意软件基于网络协议的C2 不同,Ramsay 框架采用的是自定义的文件传输控制指令,当扫描到被带入隔离网络的感染文件,则从文件特定位置读取指令执行。
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
Malicious LNK files are usually used as the exploit to trigger a vulnerability in old components of Windows, such as the Windows Shell, that allow the malware to get remote code execution with no user action required other than viewing the LNK file in Windows Explorer.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Windows operating systems have the functionality to allow nearly all application processes to load custom DLLs into their address space. This allows for the possibility of persistence, as any DLL may be loaded and executed when application processes are created on the system.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Windows operating systems have the functionality to allow nearly all application processes to load custom DLLs into their address space. This allows for the possibility of persistence, as any DLL may be loaded and executed when application processes are created on the system.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. Aquatic Panda has used DLL search-order hijacking to load exe, dll, and dat files into memory. Astaroth can launch itself via DLL Search Order Hijacking.
Phantom DLL Hijacking of Windows services: Windows Search hijacking msfte.dll, Microsoft Distributed Transaction Coordinator hijacking an Oracle dependency oci.dll.
Cobalt Strike has the ability to load DLLs via reflective injection... Lazarus Group malware sample performs reflective DLL injection... Matryoshka uses reflective DLL injection... Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Ramsay used a much more aggressive approach by automatically scanning all IP addresses in the local subnet and testing the discovered hosts to determine whether they are vulnerable to CVE-2017-0144, also known as EternalBlue.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
75 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware family/toolset cited as one of several that reused the ImprovedReflectiveDllInjection open-source library.
Document-collecting malware that scans network drives for files of interest.
Includes embedded Visual Basic scripts in malicious documents.
Cyber-espionage toolkit tailored for collecting and exfiltrating sensitive documents, including in air-gapped networks; linked to DarkHotel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.