Nymaim is a Windows malware family first documented in 2013, primarily used to download and execute additional malware. Early versions combined a first-stage downloader with a second-stage screen locker that demanded ransom payments. It subsequently evolved into a flexible malware-delivery platform with information-stealing and system-profiling capabilities. Its payloads have included ransomware and the Ursnif banking trojan. Nymaim has also incorporated web-injection functionality that monitors banking activity and modifies banking pages to facilitate fraud. The GozNym banking trojan combines Nymaim components with Gozi code.
Early campaigns distributed Nymaim through the Blackhole exploit kit and drive-by downloads. Later campaigns increasingly relied on malicious spam and phishing messages containing macro-enabled Microsoft Office documents or links to such documents. Operators have abused legitimate bulk email services and used payment, shipping, and public-health lures. Nymaim has also been delivered as a downstream payload by Emotet and PrivateLoader. Distribution has been associated with Storm-0324, Sangria Tempest, also known as FIN7, and TA564. Campaigns have affected victims internationally, including North America, Germany, Italy, and Poland.
Nymaim is notable for sophisticated custom code obfuscation and anti-analysis mechanisms. Analyzed versions detect antivirus processes, debugging and sandbox-related libraries, virtual-machine network adapters, and suspicious user or computer names. Some versions execute encrypted configuration bytecode through an embedded custom virtual machine supporting conditional logic and procedure calls. Its command-and-control mechanisms have used domain generation algorithms, transformed DNS responses, checksum validation, encrypted communications, and nameserver checks intended to avoid sinkholes. These mechanisms vary across versions; a variant observed in 2018 substantially reduced earlier obfuscation and introduced a wordlist-based domain generation algorithm.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The threat actors Sangria Tempest and Storm-0324 previously had been associated with the distribution of ... Nymaim downloader and locker.”
“The threat actors Sangria Tempest and Storm-0324 previously had been associated with the distribution of ... Nymaim downloader and locker.”
This threat actor typically targets Canada with false shipping lures, such as CanadaPost and DHL, and have attempted to deliver Ursnif, DanaBot, and Nymaim in the past.
Poland (Defunct) Polish Nymaim Medium Volume Manufacturing Campaigns began regularly in March of 2017 and appear to have gone on hiatus in May of 2018.
"Malicious Microsoft Office Document using encoded macros ... also seen for Nymaim ransomware delivery"
27 distinct techniques documented for this family, organized by ATT&CK tactic.
At that time, Nymaim was largely distributed via the Black Hole Exploit Kit (BHEK) as a "drive-by download."
In 2016, we documented distribution of the Ursnif banking Trojan via email campaigns
Nymaim ... is well known for using an advanced custom obfuscation engine, which makes it very difficult to analyse the code ... the way in which the code is written and obfuscated.
the custom "ARCH" structure known to be used by Nymaim in order to keep the aplib32 compressed data is also used by Xpaj
SignalEvent(); // pre-process termination ... Exit(0); // Exit process
Detecting sandboxing and debugging environment (IsDebugged())
The virtual machine uses IsDebugged() for anti-debugging checks, looking for blacklisted items associated with research environments: MAC addresses associated with virtual machine platform vendors VmWare, Dell, PCS Computer Systems GmbH, Microsoft Corporation, Parallels, and Xensource.
the config interpreter can communicate with other parts of the Nymaim code using a structure holding initial data, which includes: IsAdmin flag; System version from a OSVERSIONINFOEXW structure; SubAuthID; Locale obtained by GetLocaleInfoA; Pointer to the PEB
Detecting sandboxing and debugging environment (IsDebugged())
The virtual machine uses IsDebugged() for anti-debugging checks, looking for blacklisted items associated with research environments: MAC addresses associated with virtual machine platform vendors VmWare, Dell, PCS Computer Systems GmbH, Microsoft Corporation, Parallels, and Xensource.
we have discovered interesting similarities in ... the communication protocol
This screenshot shows traffic generated by the malware to its injection control IP address 31.184.234[.]21. The malware reports that the user is visiting a banking site. It then receives instructions on how to modify and replace content to initiate fraud on the user’s account.
Nymaim on its own is a dropper. It acts solely as a gateway—a delivery system for other strands of malware. GozNym uses Nymaim’s advanced stealth capabilities to unload the previously mentioned Gozi malware.
A distinctive feature of Nymaim is the DNS query for the name server record (NS). Nymaim checks if any of the answers contains a word from a list it calls BlackNsWords... If Nymaim finds any of those word in the NS resource record, it will not use the domain.
225 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader and locker mentioned as part of Storm-0324 and Sangria Tempest's historical malware distribution. No technical analysis of Nymaim is provided.
Nymaim is mentioned only as an earlier example of malware using API hammering.
Nymaim is a heavily obfuscated malware family that evolved from a dropper into a banking-capable threat. It distributes payloads, performs web injects, uses DGA and P2P communications, fingerprints infected hosts, downloads additional binaries, and can act through dropper, payload, and bot_peer modules.
Nymaim variant observed as a payload delivered by PrivateLoader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.