Nymaim

Category: loader · Aliases: None known · Sample count (EMBER 2018): 756 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Nymaim is a downloader and ransomware family active since 2013 that has been repeatedly updated to deliver banking trojans, ransomware, and click-fraud payloads. Earlier Nymaim variants delivered Gozi banking trojan; later variants pivoted to ransomware. It uses heavy anti-analysis techniques including timing checks, environment fingerprinting, and packing.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1547.001 T1071.001

Frequently Asked Questions

What is Nymaim?

Nymaim is a downloader and ransomware family active since 2013 that has been repeatedly updated to deliver banking trojans, ransomware, and click-fraud payloads. Earlier Nymaim variants delivered Gozi banking trojan; later variants pivoted to ransomware. It uses heavy anti-analysis techniques including timing checks, environment fingerprinting, and packing.

How does Nymaim spread?

Nymaim spread through exploit kits and as a downloader paired with the GozNym banking trojan campaigns.

What are the signs of a Nymaim infection?

Outbound traffic to unusual TLDs, GozNym banking injection on financial sites, and AV detections for Nymaim are diagnostic.

What should I do if I think I have Nymaim on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/nymaim.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.