{
  "family": "ramnif",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nRamnif is a heavily obfuscated alias and variant of the notorious **Ramnit** malware family. Originally discovered in 2010 as a self-replicating worm, Ramnit/Ramnif evolved into a highly sophisticated, modular Banking Trojan and botnet. It is designed for massive data theft, specifically targeting financial credentials, session cookies, and corporate FTP access.\n\n<h3>Propagation and Execution Lifecycle</h3>\nRamnif utilizes multiple vectors for distribution, including exploit kits (like Angler or RIG) hosted on compromised websites, malicious spam campaigns, and lateral movement via infected removable USB drives.\n\nOnce a host is compromised, Ramnif's operations are extensive:\n<ul>\n<li><strong>File Infection (Worm Capability):</strong> Unlike many modern trojans, Ramnif retains its original worm capabilities. It actively searches the local hard drive and attached network shares, injecting malicious code into `.exe`, `.dll`, and `.html` files. This file-infector capability makes complete eradication exceptionally difficult.</li>\n<li><strong>Web Injection and Credential Theft:</strong> Ramnif acts as a classic banking trojan. It hooks into web browsers and utilizes Man-in-the-Browser (MitB) techniques to inject malicious HTML/JavaScript into legitimate banking websites. This allows it to steal login credentials, intercept two-factor authentication (2FA) codes, and alter transaction details in real-time.</li>\n<li><strong>FTP Harvesting:</strong> The malware actively scans for and extracts stored credentials from popular FTP clients (like FileZilla or WinSCP), providing attackers with the keys to compromise external corporate web infrastructure.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nA Ramnif infection is a severe, multi-faceted security incident. It represents an immediate financial threat due to banking credential theft, while its worm-like self-replication threatens to rapidly contaminate the entire corporate network, complicating incident response efforts.\n\n<h3>Eradication and Incident Response</h3>\n<ul>\n<li><strong>Aggressive Network Isolation:</strong> Due to its file-infecting nature, infected machines must be immediately disconnected from all internal networks and VPNs to halt the infection of shared network drives.</li>\n<li><strong>Comprehensive System Re-image:</strong> Attempting to \"clean\" a Ramnif infection using antivirus software is highly risky because the malware alters legitimate system files. The only guaranteed method of eradication is a complete wipe and re-image of the compromised host from a known good baseline.</li>\n<li><strong>Enterprise Password Reset:</strong> Following containment, all credentials utilized on the infected host—especially banking, VPN, and FTP passwords—must be immediately revoked and reset.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Trojan.Ramnit",
    "Worm.Ramnif",
    "Win32/Ramnit"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1055",
    "T1056.004",
    "T1114",
    "T1091"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:35:09Z",
  "type": "Banking Trojan",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}