Skip to content

Ramnit

Ramnit is a long-running Windows malware family that originated around 2010 as a worm and file infector before evolving into a banking trojan with Zeus-derived functionality.

Profile source: Mallory opens in a new tab

Ramnit

Family profile

Ramnit is a long-running Windows malware family that originated around 2010 as a worm and file infector before evolving into a banking trojan with Zeus-derived functionality. It has been used to spy on infected users, steal banking and other credentials, inject malicious content into web sessions, harvest cookies, and download additional malware. Ramnit has also functioned as a loader for secondary payloads, including ransomware and proxy malware such as Ngioweb, and has been observed in broader criminal delivery ecosystems alongside loaders and downloaders such as sLoad and SnatchLoader.

Ramnit is notable for combining multiple capabilities in one family. Reported behaviors include credential theft, web injects against financial and payment-related sites, cookie theft, browser-focused hooking, hidden VNC-related functionality in the broader banking-malware ecosystem, custom command-and-control communications, and modular payload delivery. Some variants used a Domain Generation Algorithm for command-and-control discovery, while others relied on hardcoded infrastructure. Historical samples also exhibited file-infection behavior by appending malicious code to executable and HTML files, and some analyses described rootkit-like components, process injection, persistence mechanisms, and interference with security tooling.

Distribution has occurred through several common crimeware channels over time, including exploit kits, drive-by download campaigns, spam and malspam operations, and delivery by other malware families or loaders. Ramnit has been associated with campaigns using the RIG and Blackhole exploit kits, geographically filtered drive-by chains, and email-delivered downloader activity. It has also appeared as a follow-on payload in post-compromise activity and in malware service ecosystems linked to financially motivated actors.

Ramnit is primarily associated with financial cybercrime and online banking fraud, but its use has expanded beyond direct banking theft. It has targeted Windows users across multiple regions, with localized web-inject configurations and country-specific payloading observed in some campaigns. The family survived major disruption efforts, including a 2015 takedown, and remained active in later years. Reporting has also noted code or ecosystem relationships involving Bumblebee, Trickbot, and Conti-linked developers, although such links do not by themselves establish unified operations. Overall, Ramnit remains best characterized as a mature, adaptable Windows banking malware family with loader, theft, and post-compromise utility.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Sep 3, 2026
Feed role
C2 / Distribution
Host form
2 IP / 2 hostnames

Leading locations

  • US2
  • CN1
  • NL1

Leading providers

  • Amazon.com, Inc.1
  • California Department of Technology1
  • CHINANET Liaoning province Dalian MAN network1
  • Julian Achter1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
TA554

sLoad is a PowerShell downloader that most frequently delivers Ramnit banker... Line 13: sLoad downloading Ramnit, after receiving a command to do so.

Exploited software

Vulnerabilities linked to Ramnit

9 CVEs

MITRE ATT&CK

Ramnit in ATT&CK

50 distinct techniques

Reporting

Research mentioning Ramnit

Jan 1
Sophos Threat Research

New Lemon Duck variants exploiting Microsoft Exchange Server | SOPHOS

LemonDuck has been documented as a cross-platform malware operation that moved beyond Monero mining into credential theft, lateral movement, email propagation, security-tool tampering, and delivery of follow-on payloads on both Windows and Linux systems. Researchers said the malware spreads through phishing, USB and network shares, brute-force attacks against services including RDP, SSH, SMB, MSSQL, and Redis, and exploitation of known flaws such as CVE-2017-0144 and Microsoft Exchange ProxyLogon. The campaign also used fileless PowerShell execution, scheduled tasks, and WMI event subscriptions for persistence, while deploying components such as XMRig, password-dumping tools, and in some cases Mimikatz and Ramnit.

Jan 1
Sophos Threat Research

New Lemon Duck variants exploiting Microsoft Exchange Server | SOPHOS

Jun 15
Netbytesec

Lemon-Duck Cryptominer Technical Analysis

Aug 3
The Record Media

LemonDuck botnet evolves to allow hands-on-keyboard intrusions | The Record from Recorded Future News

Jul 29
Microsoft General

When coin miners evolve, Part 2: Hunting down LemonDuck and LemonCat attacks | Microsoft Security Blog

Jul 22
Microsoft General

When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure | Microsoft Security Blog

May 7
Talosintelligence Other

Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs

May 7
Github Web

IoCs/Trojan-LDMiner.csv at master Β· sophoslabs/IoCs Β· GitHub

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.