Skip to content

URSNIF

Ursnif, also widely known as Gozi, Gozi ISFB, and DreamBot, is a long-running Windows banking trojan and information-stealing malware family that evolved from credential theft focused on online banking into a broader post-compromise platform.

Profile source: Mallory opens in a new tab

URSNIF

Family profile

Ursnif, also widely known as Gozi, Gozi ISFB, and DreamBot, is a long-running Windows banking trojan and information-stealing malware family that evolved from credential theft focused on online banking into a broader post-compromise platform. It has been used to steal banking and financial information, browser-stored credentials, cookies, clipboard data, process information, and other host data, and it has also supported keylogging, screenshot capture, browser injection, and man-in-the-browser activity. Variants have used HiddenVNC capabilities to let operators interact with banking sessions on hidden desktops without obvious user-visible activity.

The malware has commonly been distributed through phishing and malspam campaigns, including conversation-hijacking email operations that abuse compromised accounts and trusted email threads. It has also been delivered through exploit-driven Office document campaigns, including activity leveraging CVE-2017-11882. In observed DreamBot delivery chains, victims were lured to download archives containing obfuscated script downloaders that retrieved and executed the main payload.

On infected systems, Ursnif has demonstrated anti-analysis and defense-evasion behavior, including delayed execution, environment checks, obfuscated in-memory components, and code injection into legitimate Windows processes such as Explorer. Some variants have used PowerShell download cradles during staging, section-mapping injection, and hidden execution techniques. Persistence has been established through Registry Run-key modification and installation of a copied payload in user-accessible locations.

Ursnif has been associated with browser-focused financial fraud operations, including web injection against banking and payment sites, and has been repurposed over time for broader malicious activity beyond classic banking theft. The family’s leaked source code contributed to multiple related strains and long-running confusion around naming and lineage across Gozi, ISFB, DreamBot, and Ursnif clusters. It remains most strongly associated with financially motivated cybercrime targeting Windows users and financial-account access.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Sep 1, 2026
Feed role
C2 / Distribution
Host form
9 IP / 8 hostnames

Leading locations

  • NL4
  • CH3
  • US2
  • DE1
  • TR1

Leading providers

  • servinga GmbH4
  • Datasource AG3
  • Akamai Connected Cloud1
  • OVH SAS1
  • servinga GmbH1
  • Zenlayer Inc1

Infrastructure traits

  • Hosting 11
  • Vpn 2

Samples

Recent associated samples

Reported operators

Threat actors

18 named in public reporting
TA551

In April 2022, we observed the first use of an ITG23 crypter with the Gozi banking trojan...

Hive0106

In April 2022, we observed the first use of an ITG23 crypter with the Gozi banking trojan...

Gozi ConfCrew

Maze affiliates utilize other malware and are involved with other high-end organized crimeware groups conducting systematic corporate data breaches including Zloader, Gozi and TrickBot.

TA547

The campaign pivoted from distributing the Ursnif banking trojan in early messages to later distributing Adhubllka ransomware, which encrypts files on compromised systems.

TA564

We’ve additionally seen TA564 using coronavirus emails to target Canadian users by spoofing the Public Health Agency of Canada in an attempt to deliver Ursnif. Ursnif is a common banking Trojan that can steal stored data, including passwords, from banking websites via web injections, proxies, and VNC connections.

TA544

WikiLoader has been observed installing Ursnif as a follow-on payload... The final payload in this case is the Ursnif banking trojan with GroupID “5050”.

TA554

We have observed final payloads including Ramnit, Gootkit, DarkVNC, Ursnif, and PsiXBot.

Water Minyades

Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.

TA578

TA578 since May 2020 and uses email campaigns to deliver malware like Ursnif, IcedID, KPOT Stealer, Buer Loader, and BazaLoader

Ke3chang

Ursnif is a backdoor that is used by threat actors in campaigns that lead to ransomware and data exfiltration... Ursnif is a longstanding malware that has pivoted from banking trojan to facilitating ransomware intrusions, particular for the Royal ransomware group.

ConfCrew

The malware payloads we went over include the following: AterAgent RAT Zloader Gozi CobaltStrike... if not then it will install Gozi or Zloader.

SteelClover

MSIファイルを実行することでPowerShellコードが実行されます。その結果、UrsnifとRedline Stealerがダウンロード・実行され、情報窃取が行われます。

TA577

TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.

TA571

Since the Emotet takedown, Proofpoint observed consistent, ongoing activity from The Trick, Dridex, Qbot, IcedID, ZLoader, Ursnif, and many others in our data serving as first-stage malware payloads in attempts to enable further infections, including ransomware attacks.

UNC2686

The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.

Storm-0324

Previous distribution activity associated with Storm-0324 included the Gozi infostealer and the Nymaim downloader and locker.

TA543

...dropping URLZone...which eventually led to a final Ursnif payload... We identified another Ursnif campaign... via malicious Microsoft Word documents...

TA584

TA584 has a history of using various payloads, including Ursnif and Cobalt Strike.

Exploited software

Vulnerabilities linked to URSNIF

12 CVEs

MITRE ATT&CK

URSNIF in ATT&CK

111 distinct techniques

Techniques

111 techniques
T1056 Input Capture T1059.005 Visual Basic T1071 Application Layer Protocol T1059.001 PowerShell T1566 Phishing T1082 System Information Discovery T1620 Reflective Code Loading T1497 Virtualization/Sandbox Evasion T1564 Hide Artifacts T1057 Process Discovery T1056.001 Keylogging T1055.002 Portable Executable Injection T1185 Browser Session Hijacking T1055 Process Injection T1555 Credentials from Password Stores T1041 Exfiltration Over C2 Channel T1560 Archive Collected Data T1113 Screen Capture T1059.007 JavaScript T1027 Obfuscated Files or Information T1070.004 File Deletion T1566.002 Spearphishing Link T1622 Debugger Evasion T1105 Ingress Tool Transfer T1090.003 Multi-hop Proxy T1021.005 VNC T1204.002 Malicious File T1547.001 Registry Run Keys / Startup Folder T1115 Clipboard Data T1204 User Execution T1566.001 Spearphishing Attachment T1586 Compromise Accounts T1036 Masquerading T1203 Exploitation for Client Execution T1078 Valid Accounts T1140 Deobfuscate/Decode Files or Information T1027.002 Software Packing T1112 Modify Registry T1539 Steal Web Session Cookie T1059 Command and Scripting Interpreter T1568.002 Domain Generation Algorithms T1005 Data from Local System T1055.012 Process Hollowing T1106 Native API T1564.003 Hidden Window T1071.001 Web Protocols T1014 Rootkit T1560.001 Archive via Utility T1218.011 Rundll32 T1135 Network Share Discovery T1033 System Owner/User Discovery T1012 Query Registry T1218.010 Regsvr32 T1027.013 Encrypted/Encoded File T1652 Device Driver Discovery T1056.003 Web Portal Capture T1027.007 Dynamic API Resolution T1543.003 Windows Service T1497.001 System Checks T1213 Data from Information Repositories T1129 Shared Modules T1010 Application Window Discovery T1083 File and Directory Discovery T1555.003 Credentials from Web Browsers T1056.002 GUI Input Capture T1189 Drive-by Compromise T1552 Unsecured Credentials T1547.009 Shortcut Modification T1204.001 Malicious Link T1055.004 Asynchronous Procedure Call T1047 Windows Management Instrumentation T1566.003 Spearphishing via Service T1132 Data Encoding T1559.001 Component Object Model T1090 Proxy T1007 System Service Discovery T1568 Dynamic Resolution T1602.002 Network Device Configuration Dump T1134.004 Parent PID Spoofing T1068 Exploitation for Privilege Escalation T1568.001 Fast Flux DNS T1586.002 Email Accounts T1499.001 OS Exhaustion Flood T1562.001 Disable or Modify Tools T1059.003 Windows Command Shell T1070 Indicator Removal T1218 System Binary Proxy Execution T1048 Exfiltration Over Alternative Protocol T1059.009 Cloud API T1046 Network Service Discovery T1218.005 Mshta T1585.001 Social Media Accounts T1588.001 Malware T1027.003 Steganography T1562 Impair Defenses T1583 Acquire Infrastructure T1583.001 Domains T1482 Domain Trust Discovery T1001 Data Obfuscation T1486 Data Encrypted for Impact T1016 System Network Configuration Discovery T1548.002 Bypass User Account Control T1584 Compromise Infrastructure T1104 Multi-Stage Channels T1588 Obtain Capabilities T1587.001 Malware T1055.005 Thread Local Storage T1095 Non-Application Layer Protocol T1056.004 Credential API Hooking T1090.001 Internal Proxy T1219 Remote Access Tools

Reporting

Research mentioning URSNIF

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jun 23
Github Web

DE-TH-Aura/Defender for Endpoint/ExternalData - Cert Central, CertReport.md at main · SecurityAura/DE-TH-Aura · GitHub

Jun 22
Squiblydoo

Using the Cert Graveyard - Squiblydoo.blog

May 13
Splunk Research

Detection: Cmdline Tool Not Executed In CMD Shell | Splunk Security Content

Apr 1
Squiblydoo

The CertGraveyard - Squiblydoo.blog

Mar 25
Github Web

GitHub - Squiblydoo/certReport: A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report. · GitHub

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.