Ramnit is a Windows banking trojan with file-infection, information-stealing, and additional-payload execution capabilities. First identified in 2010 as a worm, it subsequently incorporated leaked Zeus code and evolved into banking malware targeting online banking users and financial services. Its capabilities include credential and financial-data theft, screenshot capture, browser-cookie theft, information exfiltration, and execution of additional malware.
Ramnit uses browser injection and web injects to modify legitimate banking and payment pages and capture sensitive information, including credit-card data. Its modular architecture supports browser hooking, hidden VNC access, FTP credential harvesting, and interference with antivirus software. Cookie-stealing modules collect and upload cookies from multiple browsers. Some variants use a domain generation algorithm to locate command-and-control infrastructure, while others use hardcoded destinations. Analyzed campaigns used a custom command-and-control protocol with RC4-encrypted data over TCP rather than HTTPS. Ramnit samples have also incorporated Windows local privilege-escalation exploits for CVE-2013-3660 and CVE-2014-4113 to execute commands as SYSTEM.
Distribution includes malicious advertising, compromised websites, exploit-kit-driven drive-by downloads, and phishing or malspam chains using intermediary downloaders such as sLoad and SnatchLoader. Ramnit has been delivered through AdGholas malvertising and the Seamless campaign using the RIG exploit kit. TA554 has distributed it through localized, personalized email campaigns targeting the United Kingdom, Italy, and Canada. Campaigns can tailor payloads and web-inject configurations to victims’ locations, including Japanese payment services. Ramnit also serves as a delivery platform: the 2018 Black campaign deployed Ngioweb proxy malware, and other activity has delivered AZORult and ransomware as subsequent payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Our Ramnit sample exploits both CVE-2013-3660 (by PlayBit) and CVE-2014-4113 (using the same exploit code originally found as a 0-Day). | CVE-2013-3660 ... Used by the following malware families: Dyre, Ramnit.
CVE-2013-3660 Classification: 1-Day Basic Description: Uninitialized kernel pointer in EPATHOBJ::pprFlattenRec Used by the following malware families: Dyre, Ramnit | CVE-2013-3660 ... Used by the following malware families: Dyre, Ramnit.
Appendix Microsoft Defender for Endpoint detection details Antivirus Microsoft Defender Antivirus detects exploitation behavior with these detections: ... Exploit:ASP/CVE-2021-27065 ... Defending against exploits and post-compromise activities Attackers exploit the on-premises Exchange Server vulnerabilities in combination to bypass authentication and gain the ability to write files and run malicious code.
Spelevo Exploit Kitは2つの脆弱性(CVE-2018-8174とCVE-2018-15982)を悪用することが報告されていますが、PseudoGateによる攻撃ではCVE-2018-15982のみが観測されています。CVE-2018-15982はAdobe Flash PlayerのRCEの脆弱性です。
In one notable example, the Lemon Duck operators compromised a system that already had xx.bat and a web shell. After establishing persistence on the system in a non-web shell method, the Lemon Duck operators were observed cleaning up other attackers’ presence on the system and mitigating the CVE-2021-26855 (SSRF) vulnerability using a legitimate cleanup script that they hosted on their own malicious server.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
sLoad is a PowerShell downloader that most frequently delivers Ramnit banker... Line 13: sLoad downloading Ramnit, after receiving a command to do so.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
First Seamless campaign which is a Drive-by Download attack campaign uses Ramnit banking trojan.
The user reads the landing page of the RIG Exploit Kit at Gate, which attacks and sends Ramnit.
Conclusion This post has been an overview of a downloader malware known as SnatchLoader... It is being delivered via spam campaigns
The emails are crafted in the targeted country’s language and are often personalized to include recipients’ names and addresses in various parts of the email such as email body and subject. TA554 frequently uses package delivery or order notification lures; the emails contain URLs linking to zipped LNK files or zipped documents.
The original exploit for CVE-2014-4113 was part of an exploit framework in which the API passes a command-line argument, and that command is executed as SYSTEM. As that wasn’t the original API for PlayBit’s exploit, some adjustments were made and PlayBit’s exploits were re-adjusted to receive a command-line argument to be executed once elevated.
Loader introduced with remote library injection ... Masquerades Bumblebee’s main DLL as a legitimate DLL
The second argument of “getexec” command is used to specify the file name for the downloaded executable... “msiexic.exe”
Loader introduced with remote library injection ... Masquerades Bumblebee’s main DLL as a legitimate DLL
PlayBit supplies the customer with a thin wrapper around the exploit, which checks whether the target computer is indeed vulnerable. Although the check varies a bit between different exploits and versions, the basics are the same: the modification date of the vulnerable win32k driver is checked, to detect if a patch was installed.
Dubbed ‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s legitimate login page and send the inputted information to the attacker.
This file seems to be zip. Looking inside it was IE's cookies. There was a DLL module that zipped the cookie, so it might be related.
Ramnit and Hupigon are both long-standing trojans that can facilitate data theft and the delivery of additional malware. Either could have been involved in the theft of credentials attackers later reused to access the housing authority’s system
malicious svchost.exe modifies or tries to modify every binary and HTML file by appending malicious code to each file or a vbs script to HTML files
PlayBit supplies the customer with a thin wrapper around the exploit, which checks whether the target computer is indeed vulnerable. Although the check varies a bit between different exploits and versions, the basics are the same: the modification date of the vulnerable win32k driver is checked, to detect if a patch was installed.
Dubbed ‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s legitimate login page and send the inputted information to the attacker.
Two malicious files communicate with it... It and a single housing authority IP address exchanged data 5,904 times between November 2 and December 30.
Ramnit uses the original protocol when communicating with C2. Following this protocol, I try to extract the configs and modules from the traffic of Ramnit and C2. This protocol uses port 443. But, not https.
Upon infection, the sample starts to make DNS queries for many different domains in rapid succession.
It is used mainly to turn the victim’s machine into malicious proxy servers... Ngioweb represents a multifunctional proxy server... The malware can operate in two main modes: Regular back-connect proxy Relay proxy.
The main functionality of SnatchLoader is to download and load additional malware families so most of the command types and arguments are in support of doing that in various ways
Upon infection, the sample starts to make DNS queries for many different domains in rapid succession.
203 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing and banking malware family delivered by SnatchLoader in the observed campaign.
Long-standing trojan associated here with credential theft, delivery of additional malware, and in some cases ransomware as a second-stage payload.
PC banking trojan listed among malware actively used to attack companies.
Mentioned only as a prior example of certutil-based decoding technique, not as part of this campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.