Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Sep 1, 2026
- Feed role
- C2 / Distribution
- Host form
- 9 IP / 8 hostnames
Ursnif, also widely known as Gozi, Gozi ISFB, and DreamBot, is a long-running Windows banking trojan and information-stealing malware family that evolved from credential theft focused on online banking into a broader post-compromise platform.
Profile source: Mallory opens in a new tabURSNIF
Ursnif, also widely known as Gozi, Gozi ISFB, and DreamBot, is a long-running Windows banking trojan and information-stealing malware family that evolved from credential theft focused on online banking into a broader post-compromise platform. It has been used to steal banking and financial information, browser-stored credentials, cookies, clipboard data, process information, and other host data, and it has also supported keylogging, screenshot capture, browser injection, and man-in-the-browser activity. Variants have used HiddenVNC capabilities to let operators interact with banking sessions on hidden desktops without obvious user-visible activity.
The malware has commonly been distributed through phishing and malspam campaigns, including conversation-hijacking email operations that abuse compromised accounts and trusted email threads. It has also been delivered through exploit-driven Office document campaigns, including activity leveraging CVE-2017-11882. In observed DreamBot delivery chains, victims were lured to download archives containing obfuscated script downloaders that retrieved and executed the main payload.
On infected systems, Ursnif has demonstrated anti-analysis and defense-evasion behavior, including delayed execution, environment checks, obfuscated in-memory components, and code injection into legitimate Windows processes such as Explorer. Some variants have used PowerShell download cradles during staging, section-mapping injection, and hidden execution techniques. Persistence has been established through Registry Run-key modification and installation of a copied payload in user-accessible locations.
Ursnif has been associated with browser-focused financial fraud operations, including web injection against banking and payment sites, and has been repurposed over time for broader malicious activity beyond classic banking theft. The family’s leaked source code contributed to multiple related strains and long-running confusion around naming and lineage across Gozi, ISFB, DreamBot, and Ursnif clusters. It remains most strongly associated with financially motivated cybercrime targeting Windows users and financial-account access.
C2 tracking
Derp observations, rolling seven-day window
Samples
d633f17d223f276da72b75fefb9f9d78ebf477d210e65e6cd305164adb3dd4e4 4a0b858903cd039f14ba93f2b5a10b84dcf9d153c2806af226da6317ac47c00b 4e47423433e88ff4cd7dcd5c03f528cdf6c31b419c5b5e6e123dacfa4890814c 4f53a3a7829566a809a4099715d85c4bda28fd4fc0e56daaa0e542678c55b878 6f55f3937b0668f756b5ecc4b2e20fd87d8a943a8154cd8a35ba84a886b08656 abf4860525b5302cd3bc4ba6a60f7b04ec801ed4729f3217b38680be7a7048f6 364c7840077bf1d8059059d2a60fae610cadc5fc5599c398e67e723363d44d56 ac10c1b2a72c426c2f032d7da67a7b345b236587c6fb89b6406d8e57cfacb7d9 64129887cedb211bf892421f9cc0d7abfa89001f8ce04868460fe5955e497803 Reported operators
In April 2022, we observed the first use of an ITG23 crypter with the Gozi banking trojan...
In April 2022, we observed the first use of an ITG23 crypter with the Gozi banking trojan...
Maze affiliates utilize other malware and are involved with other high-end organized crimeware groups conducting systematic corporate data breaches including Zloader, Gozi and TrickBot.
The campaign pivoted from distributing the Ursnif banking trojan in early messages to later distributing Adhubllka ransomware, which encrypts files on compromised systems.
We’ve additionally seen TA564 using coronavirus emails to target Canadian users by spoofing the Public Health Agency of Canada in an attempt to deliver Ursnif. Ursnif is a common banking Trojan that can steal stored data, including passwords, from banking websites via web injections, proxies, and VNC connections.
WikiLoader has been observed installing Ursnif as a follow-on payload... The final payload in this case is the Ursnif banking trojan with GroupID “5050”.
We have observed final payloads including Ramnit, Gootkit, DarkVNC, Ursnif, and PsiXBot.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
TA578 since May 2020 and uses email campaigns to deliver malware like Ursnif, IcedID, KPOT Stealer, Buer Loader, and BazaLoader
Ursnif is a backdoor that is used by threat actors in campaigns that lead to ransomware and data exfiltration... Ursnif is a longstanding malware that has pivoted from banking trojan to facilitating ransomware intrusions, particular for the Royal ransomware group.
The malware payloads we went over include the following: AterAgent RAT Zloader Gozi CobaltStrike... if not then it will install Gozi or Zloader.
MSIファイルを実行することでPowerShellコードが実行されます。その結果、UrsnifとRedline Stealerがダウンロード・実行され、情報窃取が行われます。
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
Since the Emotet takedown, Proofpoint observed consistent, ongoing activity from The Trick, Dridex, Qbot, IcedID, ZLoader, Ursnif, and many others in our data serving as first-stage malware payloads in attempts to enable further infections, including ransomware attacks.
The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.
Previous distribution activity associated with Storm-0324 included the Gozi infostealer and the Nymaim downloader and locker.
...dropping URLZone...which eventually led to a final Ursnif payload... We identified another Ursnif campaign... via malicious Microsoft Word documents...
TA584 has a history of using various payloads, including Ursnif and Cobalt Strike.
Exploited software
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.