LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0458: Ramsay

Ramsay is an information stealing malware framework designed to collect and exfiltrate sensitive documents, including from air-gapped systems. Researchers have identified overlaps between Ramsay and the Darkhotel-associated Retro malware.[1][2]

EnterpriseS0458MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Ramsay matters because MITRE describes it as a Windows information-stealing framework designed to collect and exfiltrate sensitive documents, including from air-gapped systems. For leaders, the key issue is not only malware removal; it is whether controls around document repositories, removable media, network shares, and isolated environments can prove that sensitive data was not silently collected, staged, or moved.

Executive priority

Prioritize Ramsay as a resilience and data-protection scenario for high-value Windows environments, especially where removable media, shared drives, or air-gapped workflows are used to protect sensitive operations. Executives should ask whether the organization can evidence control over USB use, file-share access, scheduled task abuse, stealthy execution, local data staging, and outbound web traffic. This is also relevant to audit readiness because the material question after a suspected event will be: what documents were accessible, copied, staged, or potentially transferred?

Technical view

SOC and IR teams should validate coverage across the behaviors linked to Ramsay: local, removable-media, and network-share data collection; file and directory discovery; process, network configuration, network connection, service, and peripheral discovery; local data staging; scheduled task persistence or execution; Visual Basic and Native API execution; DLL injection; masquerading; obfuscation, steganography, and rootkit-style stealth; removable-media replication; tainted shared content; screen capture; and web-protocol command-and-control. Because MITRE provides no official detection text for Ramsay, detection engineering should be behavior-led rather than signature-led, with special attention to Windows hosts that bridge isolated networks and removable media workflows.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry, including scripting and Visual Basic-related execution where available
  • File creation, modification, rename, copy, and delete events on local disks, removable media, and network shared drives
  • Removable media insertion, mount, file access, and policy enforcement logs
  • Windows Scheduled Task creation, modification, and execution evidence
  • Endpoint telemetry for DLL loading, process injection indicators, native API-heavy execution, and suspicious child-process patterns

Detection direction

  • Build detections around behavior chains: discovery followed by broad document access, local staging, removable-media interaction, or web-protocol communication is more meaningful than any single event.
  • Tune monitoring for sensitive document locations and shared drives, focusing on unusual enumeration, bulk access, copying, or staging from Windows endpoints and accounts that do not normally perform those actions.
  • Validate controls and alerts for removable media use, especially on systems that connect to isolated or air-gapped environments; absence of telemetry here is a major blind spot for this malware family description.
  • Review scheduled task creation and modification for unusual names, paths, or execution of scripts/binaries from user-writable, removable, or shared locations.
  • Correlate masquerading and obfuscation signals with execution context: legitimate-looking names in unusual paths, unexpected DLL loads, and suspicious script execution can reduce false positives compared with simple filename matching.

Mitigation priorities

  • Identify Windows systems that handle sensitive documents, removable media, network shares, or air-gapped transfer workflows and treat them as priority control points.
  • Restrict and monitor removable media use; disable autorun-style behavior where applicable and require approved transfer procedures for isolated environments.
  • Apply least-privilege access to document repositories and network shares, with auditing sufficient to reconstruct file access and copying during an investigation.
  • Harden execution paths with application control, script controls, and scheduled task governance to reduce abuse of Visual Basic, native execution, DLL injection, and persistence mechanisms.
  • Improve endpoint hardening and monitoring for stealth techniques such as masquerading, obfuscated files, suspicious DLL activity, and rootkit-like attempts to hide artifacts.
Additional notes and limits

MITRE lists Ramsay as malware S0458 in enterprise ATT&CK, platform Windows, with an official description focused on information stealing and sensitive document collection/exfiltration, including from air-gapped systems. MITRE also notes researcher-identified overlaps with Darkhotel-associated Retro malware; this should be treated as research context, not as a claim of current attribution or active exploitation. The relationship set is rich and should drive defensive validation across collection, discovery, execution, persistence, lateral movement, command-and-control, and stealth behaviors.

The supplied ATT&CK object does not provide official detection guidance, aliases, labels, or object-level tactics. Several related techniques list broader platforms, but the Ramsay object itself is supplied as Windows, so local validation should focus on Windows unless separate evidence expands scope. Any assessment of exposure, compromise, or detection coverage requires environment-specific telemetry, asset context, and investigation evidence.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Ramsay

Ramsay is an information stealing malware framework designed to collect and exfiltrate sensitive documents, including from air-gapped systems. Researchers have identified overlaps between Ramsay and the Darkhotel-associated Retro malware.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

39 rows
DomainIDNameRelationship / procedure
EnterpriseT1135Network Share Discovery

Ramsay can scan for network drives which may contain documents for collection.[1][2]

EnterpriseT1559.002Dynamic Data ExchangeSub-technique

Ramsay has been delivered using OLE objects in malicious documents.[1]

EnterpriseT1113Screen Capture

Ramsay can take screenshots every 30 seconds as well as when an external removable storage device is connected.[2]

EnterpriseT1016System Network Configuration Discovery

Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables.[2]

EnterpriseT1106Native API

Ramsay can use Windows API functions such as WriteFile, CloseHandle, and GetCurrentHwProfile during its collection and file storage operations. Ramsay can execute its embedded components via CreateProcessA and ShellExecute.[1]

EnterpriseT1014Rootkit

Ramsay has included a rootkit to evade defenses.[1]

EnterpriseT1046Network Service Discovery

Ramsay can scan for systems that are vulnerable to the EternalBlue exploit.[1][2]

EnterpriseT1071.001Web ProtocolsSub-technique

Ramsay has used HTTP for C2.[2]

EnterpriseT1080Taint Shared Content

Ramsay can spread itself by infecting other portable executable files on networks shared drives.[1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Ramsay has been distributed through spearphishing emails with malicious attachments.[2]

EnterpriseT1005Data from Local System

Ramsay can collect Microsoft Word documents from the target's file system, as well as .txt, .doc, and .xls files from the Internet Explorer cache.[1][2]

EnterpriseT1053.005Scheduled TaskSub-technique

Ramsay can schedule tasks via the Windows COM API to maintain persistence.[1]

EnterpriseT1074.001Local Data StagingSub-technique

Ramsay can stage data prior to exfiltration in %APPDATA%\Microsoft\UserSetting and %APPDATA%\Microsoft\UserSetting\MediaCache.[1][2]

EnterpriseT1120Peripheral Device Discovery

Ramsay can scan for removable media which may contain documents for collection.[1][2]

EnterpriseT1574.001DLLSub-technique

Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload.[1]

EnterpriseT1039Data from Network Shared Drive

Ramsay can collect data from network drives and stage it for exfiltration.[1]

EnterpriseT1560.003Archive via Custom MethodSub-technique

Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR.[1]

EnterpriseT1560.001Archive via UtilitySub-technique

Ramsay can compress and archive collected files using WinRAR.[1][2]

EnterpriseT1203Exploitation for Client Execution

Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570.[1][2]

EnterpriseT1680Local Storage Discovery

Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators.[1][2]

EnterpriseT1027.003SteganographySub-technique

Ramsay has PE data embedded within JPEG files contained within Word documents.[2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Ramsay has masqueraded as a 7zip installer.[1][2]

EnterpriseT1057Process Discovery

Ramsay can gather a list of running processes by using Tasklist.[2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Ramsay has created Registry Run keys to establish persistence.[2]

EnterpriseT1548.002Bypass User Account ControlSub-technique

Ramsay can use UACMe for privilege escalation.[1][2]

EnterpriseT1036Masquerading

Ramsay has masqueraded as a JPG image file.[1]

EnterpriseT1119Automated Collection

Ramsay can conduct an initial scan for Microsoft Word documents on the local system, removable media, and connected network drives, before tagging and collecting them. It can continue tagging documents to collect with follow up scans.[1]

EnterpriseT1091Replication Through Removable Media

Ramsay can spread itself by infecting other portable executable files on removable drives.[1]

EnterpriseT1083File and Directory Discovery

Ramsay can collect directory and file lists.[1][2]

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

Ramsay can use ImprovedReflectiveDLLInjection to deploy components.[1]

EnterpriseT1204.002Malicious FileSub-technique

Ramsay has been executed through malicious e-mail attachments.[2]

EnterpriseT1059.005Visual BasicSub-technique

Ramsay has included embedded Visual Basic scripts in malicious documents.[1][2]

EnterpriseT1027Obfuscated Files or Information

Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers.[1]

EnterpriseT1049System Network Connections Discovery

Ramsay can use netstat to enumerate network connections.[2]

EnterpriseT1140Deobfuscate/Decode Files or Information

Ramsay can extract its agent from the body of a malicious document.[1]

EnterpriseT1132.001Standard EncodingSub-technique

Ramsay has used base64 to encode its C2 traffic.[2]

EnterpriseT1559.001Component Object ModelSub-technique

Ramsay can use the Windows COM API to schedule tasks and maintain persistence.[1]

EnterpriseT1025Data from Removable Media

Ramsay can collect data from removable media and stage it for exfiltration.[1]

EnterpriseT1546.010AppInit DLLsSub-technique

Ramsay can insert itself into the address space of other applications using the AppInit DLL Registry key.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
3c913892d2b7c0ea...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle3c913892d2b7…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  2. [2]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  3. [3]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  4. [4]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  5. [5]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  6. [6]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  7. [7]
    Ramsay

    (Citation: Eset Ramsay May 2020)

  8. [8]
    Ramsay

    (Citation: Eset Ramsay May 2020)

  9. [9]
    Ramsay

    (Citation: Eset Ramsay May 2020)

  10. [10]
    mitre-attackS0458
    Open source URL
  11. [11]
    mitre-attackS0458
    Open source URL
  12. [12]
    mitre-attackS0458
    Open source URL
  13. [13]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  14. [14]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  15. [15]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  16. [16]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  17. [17]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  18. [18]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  19. [19]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  20. [20]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  21. [21]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  22. [22]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  23. [23]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  24. [24]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  25. [25]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  26. [26]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  27. [27]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  28. [28]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  29. [29]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  30. [30]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  31. [31]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  32. [32]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  33. [33]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  34. [34]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  35. [35]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  36. [36]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  37. [37]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  38. [38]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  39. [39]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  40. [40]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  41. [41]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  42. [42]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  43. [43]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  44. [44]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  45. [45]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  46. [46]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  47. [47]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  48. [48]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  49. [49]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  50. [50]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  51. [51]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  52. [52]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  53. [53]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  54. [54]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  55. [55]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  56. [56]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  57. [57]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  58. [58]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  59. [59]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  60. [60]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  61. [61]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  62. [62]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  63. [63]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  64. [64]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  65. [65]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  66. [66]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  67. [67]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  68. [68]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  69. [69]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  70. [70]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  71. [71]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  72. [72]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  73. [73]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  74. [74]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  75. [75]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  76. [76]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  77. [77]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  78. [78]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  79. [79]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  80. [80]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  81. [81]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  82. [82]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  83. [83]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  84. [84]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  85. [85]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  86. [86]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  87. [87]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  88. [88]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  89. [89]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  90. [90]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  91. [91]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  92. [92]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  93. [93]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  94. [94]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  95. [95]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  96. [96]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  97. [97]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  98. [98]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  99. [99]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  100. [100]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  101. [101]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  102. [102]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  103. [103]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  104. [104]
    Antiy CERT Ramsay April 2020

    Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

    Open source URL
  105. [105]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  106. [106]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  107. [107]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.