Netskope Threat Labs

Nymaim

ATP Sandbox Adv. HeuristicsAV

Nymaim is a downloader family that delivered banking trojans such as Gozi through large spam campaigns. It used domain generation algorithms to resist takedowns, and its code surfaced in later families, which kept its influence visible in financial fraud malware for years.

First seen
April 2022
Last seen
October 2026
Alert Name
Binary.Trojan.Nymaim
Generic.Nymaim.E.11E9ED06
Generic.Nymaim.E.265415B7
Generic.Nymaim.E.2CF2FCAD
Generic.Nymaim.E.478A77D7
Generic.Nymaim.E.5F34870A
Generic.Nymaim.E.5FB90396
Generic.Nymaim.E.CFF71B7C
Generic.Nymaim.E.D6034B82
Generic.Nymaim.E.D702EB84