Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2
- Host form
- 0 IP / 25 hostnames
Ramnit is a long-running Windows banking trojan and malware family that has also been described in some reporting as a file-infector-capable threat.
Profile source: Mallory opens in a new tabRamnit
Ramnit is a long-running Windows banking trojan and malware family that has also been described in some reporting as a file-infector-capable threat. It is primarily associated with theft of online banking credentials and other authentication data entered through web browsers. Ramnit has been observed performing information theft and exfiltration, capturing screenshots, and executing additional files or payloads on compromised systems. Its role in criminal operations has evolved over time, with some activity indicating use not only for banking fraud but also as a loader or second-stage delivery component in broader intrusion chains.
Ramnit has been distributed through multiple delivery ecosystems. Documented infection vectors include phishing campaigns using archive files and disguised shortcut files that trigger PowerShell-based downloaders, malvertising campaigns, and exploit-kit-driven delivery. It has been delivered by intermediary malware such as sLoad and has also appeared as a payload delivered by Bedep in exploit-kit activity. These distribution patterns place Ramnit within multi-stage criminal infection chains that rely on social engineering, scripted downloaders, and browser exploitation.
Operationally, Ramnit targets Windows endpoints and focuses heavily on financial theft. Reported capabilities include stealing banking-related information, collecting authentication material from browsers, taking screenshots, and executing follow-on components. Ramnit has also been referenced alongside hidden VNC-enabled banking malware tradecraft used for interactive fraud, although HVNC use should not be generalized as a core capability without case-specific confirmation. Industry reporting has further noted that, like several legacy banking trojans, some Ramnit activity shifted over time toward enabling second-stage attacks rather than exclusively conducting direct banking fraud.
C2 tracking
Derp observations, rolling seven-day window
Samples
187979252bdf6e932753613b86202ce215132ccca8236215321c5c67b1de7875 3e68725df6872b5201f2462426b7b1b41aa8b3d7c1525b5be89f7e9d4032aac6 47ccf7af5db91cfd6774898fe25950ec95ac5a9cc44334603259b2c10bca7b8a cfecc2bc043b4b5e3d412bea8664227cb437b0deb1e75657a933e38492a8a1c8 dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 dd1bf6486965d831246279c59076aa1606cd3a81926cb6ff314c3f4ed3184455 Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.