Ramdo

First seen
2015-01-01 00:00:00
Malware type
botnet
Family
Malware family
Last IoC activity
2026-07-22 00:37:38
Profile updated
2026-07-07 15:17:17

Targeted industries: retail-and-hospitality transportation-and-logistics

Targeted regions: country_code:us country_code:jp

Context

Ramdo is a botnet malware primarily involved in ad fraud by manipulating web traffic to generate illicit advertising revenue. It is known to target retail and logistics sectors, particularly in the US and Japan.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Ramdo_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Ramdo (report)

External references