Netskope Threat Labs

Ramnit

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Ramnit is a multi purpose malware family that steals credentials and spreads through network shares and removable drives, infecting executable files as it propagates. It emerged around 2010 and blended worm spreading, banking credential theft, and downloader behavior, and law enforcement seized part of its infrastructure in 2015. Its persistence across decades reflects how file infecting worms with multiple revenue streams resist complete takedown.

First seen
January 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Worm.Ramnit
Document-HTML.Worm.Ramnit
Document-Word.Worm.Ramnit
Script-VBS.Downloader.Ramnit
Script-VBS.Trojan.Ramnit
Script-WScript.Worm.Ramnit
Trojan.HTML.Ramnit.A
Trojan.HTML.Ramnit.D
W97M.Ramnit.A
Win32.Ramnit.AQ