Skip to content

Ramnit

Ramnit is a long-running Windows banking trojan and malware family that has also been described in some reporting as a file-infector-capable threat.

Profile source: Mallory opens in a new tab

Ramnit

Family profile

Ramnit is a long-running Windows banking trojan and malware family that has also been described in some reporting as a file-infector-capable threat. It is primarily associated with theft of online banking credentials and other authentication data entered through web browsers. Ramnit has been observed performing information theft and exfiltration, capturing screenshots, and executing additional files or payloads on compromised systems. Its role in criminal operations has evolved over time, with some activity indicating use not only for banking fraud but also as a loader or second-stage delivery component in broader intrusion chains.

Ramnit has been distributed through multiple delivery ecosystems. Documented infection vectors include phishing campaigns using archive files and disguised shortcut files that trigger PowerShell-based downloaders, malvertising campaigns, and exploit-kit-driven delivery. It has been delivered by intermediary malware such as sLoad and has also appeared as a payload delivered by Bedep in exploit-kit activity. These distribution patterns place Ramnit within multi-stage criminal infection chains that rely on social engineering, scripted downloaders, and browser exploitation.

Operationally, Ramnit targets Windows endpoints and focuses heavily on financial theft. Reported capabilities include stealing banking-related information, collecting authentication material from browsers, taking screenshots, and executing follow-on components. Ramnit has also been referenced alongside hidden VNC-enabled banking malware tradecraft used for interactive fraud, although HVNC use should not be generalized as a core capability without case-specific confirmation. Industry reporting has further noted that, like several legacy banking trojans, some Ramnit activity shifted over time toward enabling second-stage attacks rather than exclusively conducting direct banking fraud.

Capabilities

  • Credential Theft
  • Exfiltration
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 6, 2026
Feed role
C2
Host form
0 IP / 25 hostnames

Leading locations

  • US20
  • IE3
  • RU2

Leading providers

  • Amazon.com, Inc.9
  • Amazon.com, Inc.8
  • Akamai Connected Cloud2
  • Google LLC2
  • Smart Technology LLC2
  • Corporation Service Company1

Infrastructure traits

  • Hosting 25
  • Vpn 4

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to Ramnit

4 CVEs

MITRE ATT&CK

Ramnit in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.