Skip to content
Malware family

Ramnit

Ramnit is a banking trojan and file-infector malware family associated with banking fraud, credential theft, and follow-on malware delivery.

Profile source: Mallory opens in a new tab

Ramnit

Family profile

Ramnit is a banking trojan and file-infector malware family associated with banking fraud, credential theft, and follow-on malware delivery. The content describes Ramnit as targeting the banking sector and notes capabilities including information exfiltration, screenshot capture, and file execution. It is also referenced as a common information stealer and as malware that has used HVNC functionality for banking fraud. Multiple delivery chains are mentioned: sLoad is described as a PowerShell-based downloader primarily used to deliver the Ramnit banking trojan, including in a phishing campaign targeting users in Ukraine that used malicious RAR/ZIP archives and a disguised PDF LNK shortcut to launch PowerShell and stage additional payloads from Bitbucket and GitHub infrastructure. Ramnit was also observed being delivered by Bedep in malvertising-driven Angler exploit kit activity, and by AdGholas/Stegano exploit kit campaigns in which downloader/Kryptik samples either contained or downloaded Ramnit. The content further notes that, like Trickbot, Zloader, and Dridex, Ramnit operators were observed shifting away from pure banking fraud toward loader-style use for second-stage attacks, often ransomware. Sekoia.io also reported a significant increase in tracked Ramnit servers in 2023.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 20, 2026
Feed role
C2 / Distribution
Host form
0 IP / 26 hostnames

Leading locations

  • US21
  • IE3
  • RU2

Leading providers

  • Amazon.com, Inc.9
  • Amazon.com, Inc.7
  • Google LLC3
  • Akamai Connected Cloud2
  • Smart Technology LLC2
  • California Department of Technology1

Infrastructure traits

  • Hosting 25
  • Vpn 5

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to Ramnit

4 CVEs

MITRE ATT&CK

Ramnit in ATT&CK

7 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.