Ramnit
Description
(Cybereason) The Ramnit Trojan is a type of malware able to exfiltrate sensitive data. This kind of data can include anything ranging from banking credentials, FTP passwords, session cookies, and personal data. Leaking this information can easily destroy user trust in a business, and in the process lose customers and ruin reputations. Luckily, our onboarding was timely, and was able to detect the trojan just as it was beginning to exfiltrate information. Our customer used our remediation tool immediately to stop the exfiltration in its tracks.
Names
Name |
---|
Ramnit |
Nimnul |
Category
Malware
Type
- Banking trojan
- Credential stealer
- Info stealer
- Exfiltration
Information
- https://www.cybereason.com/blog/banking-trojan-delivered-by-lolbins-ramnit-trojan
- https://malwarebreakdown.com/2017/08/23/the-seamless-campaign-isnt-losing-any-steam/
- http://www.nao-sec.org/2018/01/analyzing-ramnit-used-in-seamless.html
- http://contagiodump.blogspot.com/2012/01/blackhole-ramnit-samples-and-analysis.html
- https://www.cert.pl/en/news/single/ramnit-in-depth-analysis/
- https://research.checkpoint.com/ramnits-network-proxy-servers/
- http://www.vkremez.com/2018/02/deeper-dive-into-ramnit-banker-vnc-ifsb.html
- https://www.symantec.com/content/dam/symantec/docs/security-center/white-papers/w32-ramnit-analysis-15-en.pdf
- https://securityintelligence.com/posts/ramnit-banking-trojan-stealing-card-data/
Malpedia
Alienvault Otx
Other Information
Uuid
662b809d-91d0-4190-b58d-b9080d2f70c3
Last Card Change
2022-02-03