Ramsay is Windows spyware with document-collection, screen-capture, reconnaissance, and network-propagation capabilities. It collects Microsoft Word documents from local file systems and text documents, Word documents, and spreadsheets from the Internet Explorer cache. Collected files can be compressed and archived using WinRAR. Ramsay can capture screenshots every 30 seconds and when an external removable storage device is connected. It also enumerates running processes using Tasklist and gathers network configuration information, including routing information and ARP tables, using native Windows utilities.
Ramsay has been distributed through spearphishing emails containing malicious attachments, with execution triggered by users opening or running the attached files. Malicious documents can contain embedded Visual Basic scripts and an embedded agent that is extracted during execution. Ramsay has also masqueraded as a JPEG image and a 7-Zip installer.
The malware can deploy components through ImprovedReflectiveDLLInjection and launch embedded components through Windows process-creation and shell-execution APIs. It maintains persistence through scheduled tasks created using the Windows COM API and can hijack outdated application dependencies with malicious DLLs. It can use UACMe for privilege escalation and propagate by infecting portable executable files on network shared drives. Ramsay has also used Base64 encoding for command-and-control traffic.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Ramsay used a much more aggressive approach by automatically scanning all IP addresses in the local subnet and testing the discovered hosts to determine whether they are vulnerable to CVE-2017-0144, also known as EternalBlue. Note that we have not seen any Ramsay component capable of exploiting the vulnerability. | Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks ... Ramsay’s primary collection target is Microsoft Word documents ...
Ramsay ... Malicious RTF documents exploiting CVE-2017-0199 (Office/WordPad RCE), CVE-2017-11882 (Office RCE). | Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks ... Ramsay’s primary collection target is Microsoft Word documents ...
USBCulprit ... exploiting one days (CVE-2012-0158, CVE-2017-11882, CVE-2018-0802)... Retro ... Spearphishing with documents that exploit CVE-2017-11882. ... Ramsay ... Malicious RTF documents exploiting ... CVE-2017-11882 (Office RCE). | Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks ... Ramsay’s primary collection target is Microsoft Word documents ...
Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
安全厂商ESET 近日又披露了该组织新恶意框架Ramsay,Ramsay 框架是疑似专门用于针对隔离网络的恶意代码,主要通过感染正常软件进行传播,同时与常规恶意软件基于网络协议的C2 不同,Ramsay 框架采用的是自定义的文件传输控制指令,当扫描到被带入隔离网络的感染文件,则从文件特定位置读取指令执行。
39 distinct techniques documented for this family, organized by ATT&CK tactic.
80 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware family/toolset cited as one of several that reused the ImprovedReflectiveDllInjection open-source library.
Document-collecting malware that scans network drives for files of interest.
Includes embedded Visual Basic scripts in malicious documents.
Cyber-espionage toolkit tailored for collecting and exfiltrating sensitive documents, including in air-gapped networks; linked to DarkHotel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.