Ramnit is a long-running Windows malware family first observed in 2010 that evolved from a worm and file infector into a banking trojan and information-stealing platform. It has been described as Zeus-like due to code overlap and banking-focused functionality, and over time it has combined credential theft, web injection, cookie theft, browser manipulation, and modular payload delivery. Ramnit has also been associated with HiddenVNC-style remote browser abuse in the broader banking-malware ecosystem and has used custom command-and-control communications, including domain generation in some variants and hardcoded infrastructure in others.
Ramnit has been distributed through multiple intrusion vectors over its lifespan, including exploit kits, drive-by download campaigns, spam-delivered downloaders, and other malware loaders. Documented delivery chains include Blackhole and RIG exploit kit activity, as well as secondary delivery by malware such as SnatchLoader, sLoad, LemonDuck, and other criminal distribution infrastructure. Campaigns have used geofencing and victim profiling, and some operations delivered region-specific web injects tailored to financial institutions or payment-card targets.
On infected systems, Ramnit has demonstrated capabilities consistent with banking trojans and infostealers: stealing credentials and session material, injecting code into browser processes or web pages, harvesting cookies, and exfiltrating victim information to command-and-control servers. Some variants retrieved modular components for browser communication hooks, antivirus interference, FTP credential theft, and related post-compromise functions. Historical reporting also describes persistence mechanisms, process injection, rootkit capabilities, and destructive file-infection behavior in certain strains, including infection of executable and HTML files. Because of this file-infector lineage, some Ramnit infections have been considered difficult to remediate with confidence.
Ramnit has also been used as a loader for follow-on malware. A notable example is large-scale distribution of the Ngioweb proxy malware, in which Ramnit served as the initial banking-malware foothold while enabling construction of a broader proxy botnet. The family has additionally appeared in ecosystems linked to major cybercrime clusters and has been discussed alongside Bumblebee, Trickbot, Gozi, and Conti-associated development relationships, although such developer overlap is not uniformly established at the same confidence level as Ramnit’s own observed behavior.
The malware primarily targets Windows systems and has remained active across multiple years despite disruption efforts, including a major takedown in 2015. Ramnit has been used against online-banking users and broader financial targets, and later campaigns also supported credential theft, fraud enablement, and malware delivery beyond classic banking use cases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Our Ramnit sample exploits both CVE-2013-3660 (by PlayBit) and CVE-2014-4113 (using the same exploit code originally found as a 0-Day). | CVE-2013-3660 ... Used by the following malware families: Dyre, Ramnit.
CVE-2013-3660 Classification: 1-Day Basic Description: Uninitialized kernel pointer in EPATHOBJ::pprFlattenRec Used by the following malware families: Dyre, Ramnit | CVE-2013-3660 ... Used by the following malware families: Dyre, Ramnit.
Appendix Microsoft Defender for Endpoint detection details Antivirus Microsoft Defender Antivirus detects exploitation behavior with these detections: ... Exploit:ASP/CVE-2021-27065 ... Defending against exploits and post-compromise activities Attackers exploit the on-premises Exchange Server vulnerabilities in combination to bypass authentication and gain the ability to write files and run malicious code.
Spelevo Exploit Kitは2つの脆弱性(CVE-2018-8174とCVE-2018-15982)を悪用することが報告されていますが、PseudoGateによる攻撃ではCVE-2018-15982のみが観測されています。CVE-2018-15982はAdobe Flash PlayerのRCEの脆弱性です。
In one notable example, the Lemon Duck operators compromised a system that already had xx.bat and a web shell. After establishing persistence on the system in a non-web shell method, the Lemon Duck operators were observed cleaning up other attackers’ presence on the system and mitigating the CVE-2021-26855 (SSRF) vulnerability using a legitimate cleanup script that they hosted on their own malicious server.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
First Seamless campaign which is a Drive-by Download attack campaign uses Ramnit banking trojan.
The user reads the landing page of the RIG Exploit Kit at Gate, which attacks and sends Ramnit.
Conclusion This post has been an overview of a downloader malware known as SnatchLoader... It is being delivered via spam campaigns
The emails are crafted in the targeted country’s language and are often personalized to include recipients’ names and addresses in various parts of the email such as email body and subject. TA554 frequently uses package delivery or order notification lures; the emails contain URLs linking to zipped LNK files or zipped documents.
The original exploit for CVE-2014-4113 was part of an exploit framework in which the API passes a command-line argument, and that command is executed as SYSTEM. As that wasn’t the original API for PlayBit’s exploit, some adjustments were made and PlayBit’s exploits were re-adjusted to receive a command-line argument to be executed once elevated.
Loader introduced with remote library injection ... Masquerades Bumblebee’s main DLL as a legitimate DLL
The second argument of “getexec” command is used to specify the file name for the downloaded executable... “msiexic.exe”
Loader introduced with remote library injection ... Masquerades Bumblebee’s main DLL as a legitimate DLL
PlayBit supplies the customer with a thin wrapper around the exploit, which checks whether the target computer is indeed vulnerable. Although the check varies a bit between different exploits and versions, the basics are the same: the modification date of the vulnerable win32k driver is checked, to detect if a patch was installed.
malicious svchost.exe modifies or tries to modify every binary and HTML file by appending malicious code to each file or a vbs script to HTML files
PlayBit supplies the customer with a thin wrapper around the exploit, which checks whether the target computer is indeed vulnerable. Although the check varies a bit between different exploits and versions, the basics are the same: the modification date of the vulnerable win32k driver is checked, to detect if a patch was installed.
Dubbed ‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s legitimate login page and send the inputted information to the attacker.
Ramnit uses the original protocol when communicating with C2.
Ramnit uses the original protocol when communicating with C2. Following this protocol, I try to extract the configs and modules from the traffic of Ramnit and C2. This protocol uses port 443. But, not https.
Upon infection, the sample starts to make DNS queries for many different domains in rapid succession.
It is used mainly to turn the victim’s machine into malicious proxy servers... Ngioweb represents a multifunctional proxy server... The malware can operate in two main modes: Regular back-connect proxy Relay proxy.
The main functionality of SnatchLoader is to download and load additional malware families so most of the command types and arguments are in support of doing that in various ways
Upon infection, the sample starts to make DNS queries for many different domains in rapid succession.
203 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing and banking malware family delivered by SnatchLoader in the observed campaign.
PC banking trojan listed among malware actively used to attack companies.
Mentioned only as a prior example of certutil-based decoding technique, not as part of this campaign.
Banking trojan used here as the primary payload delivered by sLoad. It establishes persistence via scheduled tasks and WMI, uses reflective injection to load rmnsoft.dll into selected processes, communicates with C2 via DGA, and is described as capable of man-in-the-browser attacks, screen capture, keystroke monitoring, credential/cookie theft, downloading additional files, and uploading sensitive data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.