Ramdo
- First seen
- 2015-01-01 00:00:00
- Malware type
- botnet
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:37:38
- Profile updated
- 2026-07-07 15:17:17
Targeted industries: retail-and-hospitality transportation-and-logistics
Targeted regions: country_code:us country_code:jp
Context
Ramdo is a botnet malware primarily involved in ad fraud by manipulating web traffic to generate illicit advertising revenue. It is known to target retail and logistics sectors, particularly in the US and Japan.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Ramdo_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Ramdo (report)