logo

Nymaim revisited

ID: c71747b2-af15-5faa-9e64-d438f818f6be

STIX ID: report--c71747b2-af15-5faa-9e64-d438f818f6be

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2017-01-30

Date Updated: 2026-04-19

Author: Jarosław Jedynak

...
...

Nymaim (Goznym) is a heavily-obfuscated banking trojan analysed in this report: authors reverse-engineer its custom obfuscation, static configuration format, DGA and P2P network protocol, message encryption (RC4/Serpent/APLIB), and payload distribution. The report documents operational details (dropper/payload/bot_peer roles), extraction methods, IoCs (file hashes, YARA), and botnet measurements (thousands of supernodes, geolocated injects), and provides tooling and parsing guidance to recover configuration and injected binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.