Ramsay

S0458

Malware.View on attack.mitre.org

About this malware

Ramsay is an information stealing malware framework designed to collect and exfiltrate sensitive documents, including from air-gapped systems. Researchers have identified overlaps between Ramsay and the Darkhotel-associated Retro malware.

Techniques used39

Procedure examples39

TechniqueProcedure example
T1005
Data from Local System

Ramsay can collect Microsoft Word documents from the target's file system, as well as .txt, .doc, and .xls files from the Internet Explorer cache.

T1014
Rootkit

Ramsay has included a rootkit to evade defenses.

T1016
System Network Configuration Discovery

Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables.

T1025
Data from Removable Media

Ramsay can collect data from removable media and stage it for exfiltration.

T1027
Obfuscated Files or Information

Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers.

T1027.003
Steganography

Ramsay has PE data embedded within JPEG files contained within Word documents.

T1036
Masquerading

Ramsay has masqueraded as a JPG image file.

T1036.005
Match Legitimate Resource Name or Location

Ramsay has masqueraded as a 7zip installer.

T1039
Data from Network Shared Drive

Ramsay can collect data from network drives and stage it for exfiltration.

T1046
Network Service Discovery

Ramsay can scan for systems that are vulnerable to the EternalBlue exploit.

T1049
System Network Connections Discovery

Ramsay can use netstat to enumerate network connections.

T1053.005
Scheduled Task

Ramsay can schedule tasks via the Windows COM API to maintain persistence.

T1055.001
Dynamic-link Library Injection

Ramsay can use ImprovedReflectiveDLLInjection to deploy components.

T1057
Process Discovery

Ramsay can gather a list of running processes by using Tasklist.

T1059.005
Visual Basic

Ramsay has included embedded Visual Basic scripts in malicious documents.

View all 39 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Antiy CERT Ramsay April 2020 Open source
    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.
  2. Eset Ramsay May 2020 Open source
    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.