Ursnif

MITRE ATT&CK: S0386 View on attack.mitre.org

Aliases: Gozi-ISFB, PE_URSNIF, Dreambot, Ursnif

First seen
2007-01-01 00:00:00
Malware type
credential-stealer, trojan, spyware, backdoor
Family
Malware family
Operating systems
windows
Related IoCs
1208 (967 malicious)
Last IoC activity
2026-09-02 02:36:56
Profile updated
2026-07-07 14:58:54

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links. Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.

Recent IoC activity

967 malicious indicators in Maltiverse are attributed to Ursnif (S0386). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname nort.calag.at 2026-09-03 4
hostname adoring-driscoll.31-214-157-11.plesk.page 2026-09-03 1
hostname temniyles.ru 2026-09-03 1
hostname wxan.com 2026-09-03 1
hostname perviysneg.ru 2026-09-03 1
hostname go.in100k.at 2026-09-02 1
hostname news-deck.at 2026-09-02 3
hostname living-start.at 2026-09-02 2
hostname statusline.ru 2026-09-02 1
hostname anrfrm.msn.com 2026-09-02 1
hostname nifredao.com 2026-09-02 1
hostname line.mbclegacyllc.net 2026-09-02 2
hostname golang.feel500.at 2026-09-02 1
hostname 45-93-139-24.cprapid.com 2026-09-02 1
IP address 141.255.161.167 2026-09-01 8
hostname srcubusrctimeouthtml.info 2026-08-28 1
hostname fingerpin.cyou 2026-08-27 2
hostname new-run.pk 2026-08-16 1
hostname ya.aftnoop.at 2026-08-16 2
hostname xor055rox550ytr.com 2026-08-16 1

Detection coverage

  • 5 YARA rules
  • 682 Sigma rules

Malware & tools used

  • Registry Run Keys / Startup Folder (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Native API (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Component Object Model (attack-pattern)
  • Credential API Hooking (attack-pattern)
  • Process Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Data Encoding (attack-pattern)
  • Thread Local Storage (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Data from Local System (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Screen Capture (attack-pattern)
  • Windows Service (attack-pattern)
  • PowerShell (attack-pattern)
  • Web Protocols (attack-pattern)
  • File Deletion (attack-pattern)
  • Query Registry (attack-pattern)
  • Modify Registry (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)

Used by threat actors

Detection rules

  • EMBEERESEARCH_Win_Ursnif_Patterns_Oct_2022 (yara-rule)
  • SEKOIA_Ursnif (yara-rule)
  • SEKOIA_Ursnif_Ldr4 (yara-rule)
  • CAPE_Ursnifv3 (yara-rule)
  • CAPE_Ursnif (yara-rule)

Reports & references

  • proofpoint.com — Ursnif Variant Dreambot Adds Tor Functionality (report)
  • Mandiant — Ursnif Variant Malicious Tls Callback Technique (report)
  • MITRE ATT&CK — S0386 (report)
  • web.archive.org — Ursnif The Multifaceted Malware (report)
  • cyber.nj.gov — Ursnif (report)

External references