Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0458
MITRE ATT&CK Malware

Ramsay (S0458)

ShareXLinkedInRedditHN

[Ramsay](https://attack.mitre.org/software/S0458) is an information stealing malware framework designed to collect and exfiltrate sensitive documents, including from air-gapped systems. Researchers have identified overlaps between [Ramsay](https://attack.mitre.org/software/S0458) and the [Darkhotel](https://attack.mitre.org/groups/G0012)-associated Retro malware.(Citation: Eset Ramsay May 2020)(Citation: Antiy CERT Ramsay April 2020)

Platforms: Windows

▪Techniques implemented (39)

T1135Network Share DiscoveryT1559.002Dynamic Data ExchangeT1113Screen CaptureT1016System Network Configuration DiscoveryT1106Native APIT1014RootkitT1046Network Service DiscoveryT1071.001Web ProtocolsT1080Taint Shared ContentT1566.001Spearphishing AttachmentT1005Data from Local SystemT1053.005Scheduled TaskT1074.001Local Data StagingT1120Peripheral Device DiscoveryT1574.001DLLT1039Data from Network Shared DriveT1560.003Archive via Custom MethodT1560.001Archive via UtilityT1203Exploitation for Client ExecutionT1680Local Storage DiscoveryT1027.003SteganographyT1036.005Match Legitimate Resource Name or LocationT1057Process DiscoveryT1547.001Registry Run Keys / Startup FolderT1548.002Bypass User Account ControlT1036MasqueradingT1119Automated CollectionT1091Replication Through Removable MediaT1083File and Directory DiscoveryT1055.001Dynamic-link Library InjectionT1204.002Malicious FileT1059.005Visual BasicT1027Obfuscated Files or InformationT1049System Network Connections DiscoveryT1140Deobfuscate/Decode Files or InformationT1132.001Standard EncodingT1559.001Component Object ModelT1025Data from Removable MediaT1546.010AppInit DLLs
S0458on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.