Description
Ramnit is a multi purpose malware family that steals credentials and spreads through network shares and removable drives, infecting executable files as it propagates. It emerged around 2010 and blended worm spreading, banking credential theft, and downloader behavior, and law enforcement seized part of its infrastructure in 2015. Its persistence across decades reflects how file infecting worms with multiple revenue streams resist complete takedown.
Stats
- First seen
- January 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Worm.Ramnit |
| Document-HTML.Worm.Ramnit |
| Document-Word.Worm.Ramnit |
| Script-VBS.Downloader.Ramnit |
| Script-VBS.Trojan.Ramnit |
| Script-WScript.Worm.Ramnit |
| Trojan.HTML.Ramnit.A |
| Trojan.HTML.Ramnit.D |
| W97M.Ramnit.A |
| Win32.Ramnit.AQ |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-OTHER Js.Dropper.Ramnit payload drop attempt |




