Deep Dive: Ramnit (Worm_Banker)
Today we are analyzing the Ramnit malware family, which falls under the Worm_Banker category.
Overview
Ramnit is a worm that steals information from compromised systems. Per Malwarebytes, it downloads component files for specific tasks: one component steals cookies to hijack banking and social-media sessions, while another gives attackers remote access. It arrives via removable and fixed drives, public FTP servers, exploit kits, or bundling with potentially unwanted software. Originally a worm that evolved toward banking fraud and botnet activity, its infrastructure was targeted in law-enforcement action in 2015.
Known Aliases
Security vendors and researchers may refer to this family by several different names, including:
Ramnit
MITRE ATT&CK Techniques
This family has been observed utilizing the following techniques:
- T1091: View on MITRE
- T1547.001: View on MITRE
- T1185: View on MITRE
Frequently Asked Questions
What is Ramnit?
A worm that steals information from infected systems, including banking and social-media session data, and can grant attackers remote access.
How does Ramnit steal banking information?
One of its downloadable components steals cookies, which can be used to hijack banking and social-media sessions.
How does Ramnit spread?
Via removable and fixed drives, public FTP servers, exploit kits, and bundling with potentially unwanted software.
Can Ramnit give attackers remote control?
Yes; one of its components is capable of providing threat actors remote access to the affected system.
Was Ramnit ever disrupted?
Its botnet infrastructure was targeted in a 2015 law-enforcement operation, though the family continued to be observed afterward.
How can I reduce the risk from Ramnit?
Disable autorun on removable drives, be cautious with bundled/unwanted software and downloads, keep systems patched, and use reputable security software.
Where can I read an authoritative source on Ramnit?
Malwarebytes maintains a Worm.Ramnit detection page, linked on this page.
This article is part of the Malware Families Catalog. Visit the original page for more details and interactive data! You can also find the full dataset on Hugging Face and Kaggle.
Top comments (0)