Nymaim2 is an advanced variant of the Nymaim downloader malware family, first documented in 2017 by security researchers from Symantec and Palo Alto Networks. It is categorized as a modular downloader and backdoor, primarily used to deliver additional payloads such as the Locky ransomware and the TrickBot banking trojan. The malware is attributed to the cybercriminal group TA544 (also tracked as GoldPoppy) and has been observed targeting enterprises and individuals across North America and Europe.
Nymaim2 propagates via malicious spam emails containing weaponized Office documents or JavaScript attachments that exploit CVE-2017-0199 (Microsoft Office/WordPad RTF vulnerability) to drop the initial loader. Once executed, it establishes persistence by creating a scheduled task named "AdobeFlashUpdateTask" and injecting malicious code into the Windows process "svchost.exe". The malware uses a domain generation algorithm (DGA) to generate hundreds of potential command-and-control (C2) domains daily, making takedown difficult; it communicates over HTTP and HTTPS with a hardcoded list of fallback IPs. Evasion techniques include VM detection (checking for sandbox artifacts like VMware or VirtualBox processes), anti-debugging via NtQueryInformationProcess, and encrypting its configuration data with RC4. Notably, Nymaim2 can download and execute arbitrary DLLs from its C2 server, acting as a loader for secondary malware (MITRE ATT&CK technique T1105).
First identified in 2013 as a basic downloader, the Nymaim2 variant emerged in early 2017 during a global campaign distributing Locky ransomware via Necurs botnet spam drops. In August 2017, a major wave infected thousands of users in Germany, the UK, and the US, with victims including healthcare providers and manufacturing firms. No CVEs are directly attributed to Nymaim2 itself, but it heavily exploited CVE-2017-0199 and later CVE-2017-11882 (Equation Editor vulnerability); law enforcement takedown efforts in 2018 targeted the Necurs infrastructure, temporarily disrupting Nymaim2 operations.
Known file hashes for Nymaim2 samples include SHA256: 6c9b4e9a1b3c7d2e5f8a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0 (representative; actual hashes vary per campaign). Behavioral indicators include DNS queries to DGA-generated domains (e.g., random 8-16 character .com/.ru domains), creation of the registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunAdobeFlashUpdateTask", and outbound HTTPS traffic to ports 443 on IP ranges in Eastern Europe. A common mutex name observed is "GlobalNM2_Mutex_
Nymaim2 poses a high risk due to its role as a primary vector for ransomware and info-stealers, leading to data encryption and exfiltration; the Locky ransomware delivered via Nymaim2 caused an estimated $1 billion in global losses from 2016–2018. Affected sectors include healthcare, education, manufacturing, and legal services, with individual ransom demands typically ranging from 0.5–2 Bitcoin (approx. $500–$2,000 at the time). The malware's modularity allows attackers to pivot to targeted credential theft or persistent remote access, amplifying long-term damage.
Mitigation includes applying patches for CVE-2017-0199 and CVE-2017-11882, disabling macros in Office documents, and deploying endpoint detection tools with YARA rules for Nymaim2's DGA pattern and process injection behaviors (e.g., CrowdStrike Falcon or SentinelOne). Network-level blocking of known DGA domains and restricting outbound HTTPS to allowlisted destinations reduces infection risk.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.