Ursnif
MITRE ATT&CK: S0386 View on attack.mitre.org
Aliases: Gozi-ISFB, PE_URSNIF, Dreambot, Ursnif
- First seen
- 2007-01-01 00:00:00
- Malware type
- credential-stealer, trojan, spyware, backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1208 (967 malicious)
- Last IoC activity
- 2026-09-02 02:36:56
- Profile updated
- 2026-07-07 14:58:54
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality
Context
Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links. Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.
Recent IoC activity
967 malicious indicators in Maltiverse are attributed to Ursnif (S0386). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | nort.calag.at | 2026-09-03 | 4 |
| hostname | adoring-driscoll.31-214-157-11.plesk.page | 2026-09-03 | 1 |
| hostname | temniyles.ru | 2026-09-03 | 1 |
| hostname | wxan.com | 2026-09-03 | 1 |
| hostname | perviysneg.ru | 2026-09-03 | 1 |
| hostname | go.in100k.at | 2026-09-02 | 1 |
| hostname | news-deck.at | 2026-09-02 | 3 |
| hostname | living-start.at | 2026-09-02 | 2 |
| hostname | statusline.ru | 2026-09-02 | 1 |
| hostname | anrfrm.msn.com | 2026-09-02 | 1 |
| hostname | nifredao.com | 2026-09-02 | 1 |
| hostname | line.mbclegacyllc.net | 2026-09-02 | 2 |
| hostname | golang.feel500.at | 2026-09-02 | 1 |
| hostname | 45-93-139-24.cprapid.com | 2026-09-02 | 1 |
| IP address | 141.255.161.167 | 2026-09-01 | 8 |
| hostname | srcubusrctimeouthtml.info | 2026-08-28 | 1 |
| hostname | fingerpin.cyou | 2026-08-27 | 2 |
| hostname | new-run.pk | 2026-08-16 | 1 |
| hostname | ya.aftnoop.at | 2026-08-16 | 2 |
| hostname | xor055rox550ytr.com | 2026-08-16 | 1 |
Detection coverage
- 5 YARA rules
- 682 Sigma rules
Malware & tools used
- Registry Run Keys / Startup Folder (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Local Data Staging (attack-pattern)
- Native API (attack-pattern)
- Time Based Checks (attack-pattern)
- Component Object Model (attack-pattern)
- Credential API Hooking (attack-pattern)
- Process Discovery (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Data Encoding (attack-pattern)
- Thread Local Storage (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Data from Local System (attack-pattern)
- Command Obfuscation (attack-pattern)
- Screen Capture (attack-pattern)
- Windows Service (attack-pattern)
- PowerShell (attack-pattern)
- Web Protocols (attack-pattern)
- File Deletion (attack-pattern)
- Query Registry (attack-pattern)
- Modify Registry (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
Used by threat actors
- TA551 (threat-actor)
Detection rules
- EMBEERESEARCH_Win_Ursnif_Patterns_Oct_2022 (yara-rule)
- SEKOIA_Ursnif (yara-rule)
- SEKOIA_Ursnif_Ldr4 (yara-rule)
- CAPE_Ursnifv3 (yara-rule)
- CAPE_Ursnif (yara-rule)
Reports & references
- proofpoint.com — Ursnif Variant Dreambot Adds Tor Functionality (report)
- Mandiant — Ursnif Variant Malicious Tls Callback Technique (report)
- MITRE ATT&CK — S0386 (report)
- web.archive.org — Ursnif The Multifaceted Malware (report)
- cyber.nj.gov — Ursnif (report)
External references
- mitre-attack — S0386
- Gozi-ISFB
- Ursnif
- Dreambot
- PE_URSNIF
- TrendMicro Ursnif Mar 2015
- NJCCIC Ursnif Sept 2016
- ProofPoint Ursnif Aug 2016
- FireEye Ursnif Nov 2017
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy