Skip to content
Malware family

URSNIF

Ursnif, also referred to in the content as Gozi, Gozi-ISFB, and Dreambot-related ISFB variants, is a common banking Trojan/backdoor in the Gozi/ISFB malware family.

Profile source: Mallory opens in a new tab

URSNIF

Family profile

Ursnif, also referred to in the content as Gozi, Gozi-ISFB, and Dreambot-related ISFB variants, is a common banking Trojan/backdoor in the Gozi/ISFB malware family. The content describes it as capable of stealing stored data and banking credentials, including via web injections, and supporting proxy and VNC connections; it can also update itself or install additional modules remotely. Related ISFB-family capabilities described in the content include victim fingerprinting, keylogging, form grabbing, browser replacement attacks, screen recording, email theft, file theft, SOCKS proxying, and second-stage payload delivery, with operators increasingly using it as a loader or entry point for follow-on attacks including ransomware.

Observed behavior in the content is primarily Windows-focused. Ursnif has queried the Registry for installed programs, modified the Registry as part of installation, and registered itself as a system service in the Registry for automatic execution at startup. Ursnif droppers have used COM properties to execute malware in hidden windows. The malware has also been observed manipulating TLS callbacks while injecting a child process. The content additionally notes that Ursnif droppers have used a large number of export functions, and one referenced variant employed a malicious TLS callback technique for process injection.

Infection and delivery vectors mentioned in the content include phishing and malspam ecosystems, exploit-kit delivery, and distribution by other malware. TA551 (Shathak/Gold Cabin) is described as spreading Ursnif, and TA577 is reported to have delivered Ursnif in phishing campaigns since 2020. Proofpoint tracked Ursnif in Japan-focused campaigns since at least 2017, including URLZone/Bebloh/Shiotob infections in which URLZone first infected the host and then downloaded Ursnif configured with web injects for Japanese banks; TA544 was attributed much of that Japan-focused activity. BrushaLoader was observed delivering Ursnif in Italy. Danabot has distributed Ursnif as a secondary payload, and the content also references delivery through Angler/Bedep-era malvertising and exploit-kit activity.

Targeting in the content centers on financial theft and banking fraud, with specific references to campaigns targeting Japan and Italy and to Dreambot/ISFB activity against banks in Germany and other countries. Threat-actor and ecosystem associations explicitly mentioned include TA551, TA577, TA544, TA547, and Danabot distributors, as well as broader ISFB/Dreambot criminal operations. The content also notes infrastructure observations from a June 2023 Ursnif campaign targeting Italy, where multiple remote destinations hosting Ursnif tier-1 command-and-control shared the hostname WIN-LIVFRVQFMKO.

High-confidence indicators and artifacts directly mentioned in the content include the shared hostname WIN-LIVFRVQFMKO on infrastructure tied to a June 2023 Ursnif campaign targeting Italy, and an example Ursnif C2 domain browneyandrebun[.]net associated with fileless Ursnif activity observed in November 2015.

Reported operators

Threat actors

10 named in public reporting
TA551

TA551, also known as Shathak or Gold Cabin, is an attacker group that is responsible for spreading a wide variety of malware families including IcedID, Valak, Ursnif and, more recently, BazarLoader.

TA577

TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.

TA547

Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.

TA544

Ursnif is a common banking Trojan that can: Steal stored data including passwords from banking websites via web injections, proxies and VNC connections Update itself or install modules remotely.

TA571

Since the Emotet takedown, Proofpoint observed consistent, ongoing activity from The Trick, Dridex, Qbot, IcedID, ZLoader, Ursnif, and many others in our data serving as first-stage malware payloads in attempts to enable further infections, including ransomware attacks.

UNC2686

The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.

TA578

TA578 has previously been observed in email-based campaigns delivering Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, and Cobalt Strike.

Storm-0324

Previous distribution activity associated with Storm-0324 included the Gozi infostealer and the Nymaim downloader and locker.

TA543

...dropping URLZone...which eventually led to a final Ursnif payload... We identified another Ursnif campaign... via malicious Microsoft Word documents...

TA584

TA584 has a history of using various payloads, including Ursnif and Cobalt Strike.

Exploited software

Vulnerabilities linked to URSNIF

4 CVEs

MITRE ATT&CK

URSNIF in ATT&CK

74 distinct techniques

Techniques

74 techniques
T1059.003 Windows Command Shell T1112 Modify Registry T1082 System Information Discovery T1012 Query Registry T1547.001 Registry Run Keys / Startup Folder T1055.005 Thread Local Storage T1568 Dynamic Resolution T1095 Non-Application Layer Protocol T1056.004 Credential API Hooking T1090.003 Multi-hop Proxy T1090.001 Internal Proxy T1568.002 Domain Generation Algorithms T1219 Remote Access Tools T1056.003 Web Portal Capture T1071.001 Web Protocols T1056.001 Keylogging T1566.003 Spearphishing via Service T1105 Ingress Tool Transfer T1041 Exfiltration Over C2 Channel T1568.001 Fast Flux DNS T1560 Archive Collected Data T1189 Drive-by Compromise T1185 Browser Session Hijacking T1566 Phishing T1071 Application Layer Protocol T1543.003 Windows Service T1564.003 Hidden Window T1140 Deobfuscate/Decode Files or Information T1566.001 Spearphishing Attachment T1497.001 System Checks T1608.001 Upload Malware T1059.001 PowerShell T1204.002 Malicious File T1059 Command and Scripting Interpreter T1027.003 Steganography T1656 Impersonation T1497 Virtualization/Sandbox Evasion T1059.005 Visual Basic T1027 Obfuscated Files or Information T1204 User Execution T1070.004 File Deletion T1074 Data Staged T1649 Steal or Forge Authentication Certificates T1005 Data from Local System T1057 Process Discovery T1036.005 Match Legitimate Resource Name or Location T1036 Masquerading T1047 Windows Management Instrumentation T1560.001 Archive via Utility T1218 System Binary Proxy Execution T1113 Screen Capture T1129 Shared Modules T1486 Data Encrypted for Impact T1059.007 JavaScript T1620 Reflective Code Loading T1055 Process Injection T1090.004 Domain Fronting T1027.013 Encrypted/Encoded File T1106 Native API T1566.002 Spearphishing Link T1007 System Service Discovery T1055.012 Process Hollowing T1204.001 Malicious Link T1555.003 Credentials from Web Browsers T1003 OS Credential Dumping T1021 Remote Services T1559.001 Component Object Model T1080 Taint Shared Content T1090 Proxy T1074.001 Local Data Staging T1132 Data Encoding T1027.010 Command Obfuscation T1091 Replication Through Removable Media T1497.003 Time Based Checks

Reporting

Research mentioning URSNIF

Jun 5
Mandiant Threat Intelligence

Ongoing Targeted Campaign Against US Law Firms | Google Cloud Blog

The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.

May 7
R136a1

Where Have All the Complex Windows Malware and Their Analyses Gone?

Even the commodity malware scene was a fascinating technical playground, where researchers regularly hunted down and deconstructed heavyweights like TDL, ZeroAccess, Zeus, Dridex, Ursnif, Ploutus, and Carberp — again, just to name a few.

Feb 25
Splunk Research

Detection: BITSAdmin Download File | Splunk Security Content

Associated Analytic Story ... Gozi Malware

Feb 25
Splunk Research

Detection: Windows Suspicious C2 Named Pipe | Splunk Security Content

Associated Analytic Story APT37 Rustonotto and FadeStealer, BlackByte Ransomware, Brute Ratel C4, Cobalt Strike, DarkSide Ransomware, Gozi Malware, Graceful Wipe Out Attack, Hellcat Ransomware, LockBit Ransomware, Meterpreter, Remote Monitoring and Management Software, Storm-0501 Ransomware, Trickbot, Tuoni

Feb 25
Splunk Research

Detection: Windows RMM Named Pipe | Splunk Security Content

Associated Analytic Story ... Gozi Malware

Feb 25
Splunk Research

Detection: Detect Remote Access Software Usage FileInfo | Splunk Security Content

Associated Analytic Story Cactus Ransomware ... Gozi Malware ... The following analytic detects the execution of processes with file or code signing attributes from known remote access software within the environment.

Feb 25
Splunk Research

Detection: Detect Remote Access Software Usage Process | Splunk Security Content

Associated Analytic Story ... Gozi Malware

Feb 10
The Hacker News

Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools

...multiple ransomware operators, including LockBit, Qilin, Conti, BlackCat, and Ursnif, as well as various malware campaigns...

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.