GOLD FAIRFAX
Objectives
Tools
SUMMARY
GOLD FAIRFAX was a financially motivated cybercriminal threat group responsible for the creation, distribution, and operation of the Ramnit botnet. Ramnit, the phonetic spelling of RMNet, the internal name of the core module, began operation in April 2010 and became widespread in July 2010. A particularly virulent file-infecting component of early Ramnit variants that spreads by modifying executables and HTML files has resulted in the continued prevalence of those early variants. The primary intent of Ramnit was to intercept and manipulate online financial transactions through modification of web browser behavior ("man-in-the-browser"). Ramnit could also download and execute additional malware payloads. GOLD FAIRFAX ceased distributing Ramnit in early 2020.
Contact Us
Contact us directly whether your organization needs immediate assistance or you want to discuss your incident readiness, response, and testing needs.