Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 2 hostnames
Ramnit is a long-running Windows malware family that originated around 2010 as a worm and file infector before evolving into a banking trojan with Zeus-derived functionality.
Profile source: Mallory opens in a new tabRamnit
Ramnit is a long-running Windows malware family that originated around 2010 as a worm and file infector before evolving into a banking trojan with Zeus-derived functionality. It has been used to spy on infected users, steal banking and other credentials, inject malicious content into web sessions, harvest cookies, and download additional malware. Ramnit has also functioned as a loader for secondary payloads, including ransomware and proxy malware such as Ngioweb, and has been observed in broader criminal delivery ecosystems alongside loaders and downloaders such as sLoad and SnatchLoader.
Ramnit is notable for combining multiple capabilities in one family. Reported behaviors include credential theft, web injects against financial and payment-related sites, cookie theft, browser-focused hooking, hidden VNC-related functionality in the broader banking-malware ecosystem, custom command-and-control communications, and modular payload delivery. Some variants used a Domain Generation Algorithm for command-and-control discovery, while others relied on hardcoded infrastructure. Historical samples also exhibited file-infection behavior by appending malicious code to executable and HTML files, and some analyses described rootkit-like components, process injection, persistence mechanisms, and interference with security tooling.
Distribution has occurred through several common crimeware channels over time, including exploit kits, drive-by download campaigns, spam and malspam operations, and delivery by other malware families or loaders. Ramnit has been associated with campaigns using the RIG and Blackhole exploit kits, geographically filtered drive-by chains, and email-delivered downloader activity. It has also appeared as a follow-on payload in post-compromise activity and in malware service ecosystems linked to financially motivated actors.
Ramnit is primarily associated with financial cybercrime and online banking fraud, but its use has expanded beyond direct banking theft. It has targeted Windows users across multiple regions, with localized web-inject configurations and country-specific payloading observed in some campaigns. The family survived major disruption efforts, including a 2015 takedown, and remained active in later years. Reporting has also noted code or ecosystem relationships involving Bumblebee, Trickbot, and Conti-linked developers, although such links do not by themselves establish unified operations. Overall, Ramnit remains best characterized as a mature, adaptable Windows banking malware family with loader, theft, and post-compromise utility.
C2 tracking
Derp observations, rolling seven-day window
Samples
58bf3744e13bbdfd1dc8439b2462fdbc8374b2f1f06bb5aed6cc0a04ad2659c8 7798e3cf43ab05426aa76b9f00ce1df77900bba455eaf497a988fe9afae82e45 7fc9190fb8464d3be3e126165cc79e1e8be8cd3b13bffee953986001c06b6150 b121749a18da7722884fd1878950bb11ae65258555065c42ce699f7c08b82aa8 e427626e6c685d97cab0ca40620ea5c02c2f5ecf090bbe2cf24b65928c6a669e 15f2d2900fb4061cbdc9fe5ed39b4a6995bb439e0eb5db8740c0321da2d1f37e 3d08ef00c7b7c1ae32bbe32503644d7fbf4b34b9cbfa89c9a4aacd4a74691fdb 43c88dcbe8895a98a8979cbe77b31db8773e4d98f6f4024933f1db00ada2f1fa 4b011357b73086f36c88caa9fd2b85f5030bf7124c2878a0a80166bcf15ba1f2 68832065c1e9dca5f016465885d28338bcbe921fc2c33c38cbe2759e79b5dd11 Reported operators
sLoad is a PowerShell downloader that most frequently delivers Ramnit banker... Line 13: sLoad downloading Ramnit, after receiving a command to do so.
Exploited software
MITRE ATT&CK
Reporting
LemonDuck has been documented as a cross-platform malware operation that moved beyond Monero mining into credential theft, lateral movement, email propagation, security-tool tampering, and delivery of follow-on payloads on both Windows and Linux systems. Researchers said the malware spreads through phishing, USB and network shares, brute-force attacks against services including RDP, SSH, SMB, MSSQL, and Redis, and exploitation of known flaws such as CVE-2017-0144 and Microsoft Exchange ProxyLogon. The campaign also used fileless PowerShell execution, scheduled tasks, and WMI event subscriptions for persistence, while deploying components such as XMRig, password-dumping tools, and in some cases Mimikatz and Ramnit.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.