TA551, also known as Shathak or Gold Cabin, is an attacker group that is responsible for spreading a wide variety of malware families including IcedID, Valak, Ursnif and, more recently, BazarLoader.
URSNIF
Ursnif, also referred to in the content as Gozi, Gozi-ISFB, and Dreambot-related ISFB variants, is a common banking Trojan/backdoor in the Gozi/ISFB malware family.
Profile source: Mallory opens in a new tabURSNIF
Family profile
Ursnif, also referred to in the content as Gozi, Gozi-ISFB, and Dreambot-related ISFB variants, is a common banking Trojan/backdoor in the Gozi/ISFB malware family. The content describes it as capable of stealing stored data and banking credentials, including via web injections, and supporting proxy and VNC connections; it can also update itself or install additional modules remotely. Related ISFB-family capabilities described in the content include victim fingerprinting, keylogging, form grabbing, browser replacement attacks, screen recording, email theft, file theft, SOCKS proxying, and second-stage payload delivery, with operators increasingly using it as a loader or entry point for follow-on attacks including ransomware.
Observed behavior in the content is primarily Windows-focused. Ursnif has queried the Registry for installed programs, modified the Registry as part of installation, and registered itself as a system service in the Registry for automatic execution at startup. Ursnif droppers have used COM properties to execute malware in hidden windows. The malware has also been observed manipulating TLS callbacks while injecting a child process. The content additionally notes that Ursnif droppers have used a large number of export functions, and one referenced variant employed a malicious TLS callback technique for process injection.
Infection and delivery vectors mentioned in the content include phishing and malspam ecosystems, exploit-kit delivery, and distribution by other malware. TA551 (Shathak/Gold Cabin) is described as spreading Ursnif, and TA577 is reported to have delivered Ursnif in phishing campaigns since 2020. Proofpoint tracked Ursnif in Japan-focused campaigns since at least 2017, including URLZone/Bebloh/Shiotob infections in which URLZone first infected the host and then downloaded Ursnif configured with web injects for Japanese banks; TA544 was attributed much of that Japan-focused activity. BrushaLoader was observed delivering Ursnif in Italy. Danabot has distributed Ursnif as a secondary payload, and the content also references delivery through Angler/Bedep-era malvertising and exploit-kit activity.
Targeting in the content centers on financial theft and banking fraud, with specific references to campaigns targeting Japan and Italy and to Dreambot/ISFB activity against banks in Germany and other countries. Threat-actor and ecosystem associations explicitly mentioned include TA551, TA577, TA544, TA547, and Danabot distributors, as well as broader ISFB/Dreambot criminal operations. The content also notes infrastructure observations from a June 2023 Ursnif campaign targeting Italy, where multiple remote destinations hosting Ursnif tier-1 command-and-control shared the hostname WIN-LIVFRVQFMKO.
High-confidence indicators and artifacts directly mentioned in the content include the shared hostname WIN-LIVFRVQFMKO on infrastructure tied to a June 2023 Ursnif campaign targeting Italy, and an example Ursnif C2 domain browneyandrebun[.]net associated with fileless Ursnif activity observed in November 2015.
Reported operators
Threat actors
10 named in public reportingTA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
Ursnif is a common banking Trojan that can: Steal stored data including passwords from banking websites via web injections, proxies and VNC connections Update itself or install modules remotely.
Since the Emotet takedown, Proofpoint observed consistent, ongoing activity from The Trick, Dridex, Qbot, IcedID, ZLoader, Ursnif, and many others in our data serving as first-stage malware payloads in attempts to enable further infections, including ransomware attacks.
The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.
TA578 has previously been observed in email-based campaigns delivering Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, and Cobalt Strike.
Previous distribution activity associated with Storm-0324 included the Gozi infostealer and the Nymaim downloader and locker.
...dropping URLZone...which eventually led to a final Ursnif payload... We identified another Ursnif campaign... via malicious Microsoft Word documents...
TA584 has a history of using various payloads, including Ursnif and Cobalt Strike.
Exploited software
Vulnerabilities linked to URSNIF
4 CVEsMITRE ATT&CK
URSNIF in ATT&CK
74 distinct techniquesTechniques
74 techniquesReporting
Research mentioning URSNIF
Ongoing Targeted Campaign Against US Law Firms | Google Cloud Blog
The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.
Where Have All the Complex Windows Malware and Their Analyses Gone?
Even the commodity malware scene was a fascinating technical playground, where researchers regularly hunted down and deconstructed heavyweights like TDL, ZeroAccess, Zeus, Dridex, Ursnif, Ploutus, and Carberp — again, just to name a few.
Detection: BITSAdmin Download File | Splunk Security Content
Associated Analytic Story ... Gozi Malware
Detection: Windows Suspicious C2 Named Pipe | Splunk Security Content
Associated Analytic Story APT37 Rustonotto and FadeStealer, BlackByte Ransomware, Brute Ratel C4, Cobalt Strike, DarkSide Ransomware, Gozi Malware, Graceful Wipe Out Attack, Hellcat Ransomware, LockBit Ransomware, Meterpreter, Remote Monitoring and Management Software, Storm-0501 Ransomware, Trickbot, Tuoni
Detection: Windows RMM Named Pipe | Splunk Security Content
Associated Analytic Story ... Gozi Malware
Detection: Detect Remote Access Software Usage FileInfo | Splunk Security Content
Associated Analytic Story Cactus Ransomware ... Gozi Malware ... The following analytic detects the execution of processes with file or code signing attributes from known remote access software within the environment.
Detection: Detect Remote Access Software Usage Process | Splunk Security Content
Associated Analytic Story ... Gozi Malware
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools
...multiple ransomware operators, including LockBit, Qilin, Conti, BlackCat, and Ursnif, as well as various malware campaigns...