Skip to main content

Boteraser | Website and Server Security Solutions

Nymaim2

Malware

⚠️ Overview

Nymaim2 is an advanced variant of the Nymaim downloader malware family, first documented in 2017 by security researchers from Symantec and Palo Alto Networks. It is categorized as a modular downloader and backdoor, primarily used to deliver additional payloads such as the Locky ransomware and the TrickBot banking trojan. The malware is attributed to the cybercriminal group TA544 (also tracked as GoldPoppy) and has been observed targeting enterprises and individuals across North America and Europe.

🔧 Technical Capabilities

Nymaim2 propagates via malicious spam emails containing weaponized Office documents or JavaScript attachments that exploit CVE-2017-0199 (Microsoft Office/WordPad RTF vulnerability) to drop the initial loader. Once executed, it establishes persistence by creating a scheduled task named "AdobeFlashUpdateTask" and injecting malicious code into the Windows process "svchost.exe". The malware uses a domain generation algorithm (DGA) to generate hundreds of potential command-and-control (C2) domains daily, making takedown difficult; it communicates over HTTP and HTTPS with a hardcoded list of fallback IPs. Evasion techniques include VM detection (checking for sandbox artifacts like VMware or VirtualBox processes), anti-debugging via NtQueryInformationProcess, and encrypting its configuration data with RC4. Notably, Nymaim2 can download and execute arbitrary DLLs from its C2 server, acting as a loader for secondary malware (MITRE ATT&CK technique T1105).

📜 History & Notable Incidents

First identified in 2013 as a basic downloader, the Nymaim2 variant emerged in early 2017 during a global campaign distributing Locky ransomware via Necurs botnet spam drops. In August 2017, a major wave infected thousands of users in Germany, the UK, and the US, with victims including healthcare providers and manufacturing firms. No CVEs are directly attributed to Nymaim2 itself, but it heavily exploited CVE-2017-0199 and later CVE-2017-11882 (Equation Editor vulnerability); law enforcement takedown efforts in 2018 targeted the Necurs infrastructure, temporarily disrupting Nymaim2 operations.

🔍 Detection Indicators

Known file hashes for Nymaim2 samples include SHA256: 6c9b4e9a1b3c7d2e5f8a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0 (representative; actual hashes vary per campaign). Behavioral indicators include DNS queries to DGA-generated domains (e.g., random 8-16 character .com/.ru domains), creation of the registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunAdobeFlashUpdateTask", and outbound HTTPS traffic to ports 443 on IP ranges in Eastern Europe. A common mutex name observed is "GlobalNM2_Mutex_". Network analysts often detect unusual User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0" associated with C2 payloads.

☠️ Risk & Impact

Nymaim2 poses a high risk due to its role as a primary vector for ransomware and info-stealers, leading to data encryption and exfiltration; the Locky ransomware delivered via Nymaim2 caused an estimated $1 billion in global losses from 2016–2018. Affected sectors include healthcare, education, manufacturing, and legal services, with individual ransom demands typically ranging from 0.5–2 Bitcoin (approx. $500–$2,000 at the time). The malware's modularity allows attackers to pivot to targeted credential theft or persistent remote access, amplifying long-term damage.

🛡️ Mitigation

Mitigation includes applying patches for CVE-2017-0199 and CVE-2017-11882, disabling macros in Office documents, and deploying endpoint detection tools with YARA rules for Nymaim2's DGA pattern and process injection behaviors (e.g., CrowdStrike Falcon or SentinelOne). Network-level blocking of known DGA domains and restricting outbound HTTPS to allowlisted destinations reduces infection risk.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.