Ursnif, also widely known as Gozi, Gozi ISFB, and DreamBot, is a long-running Windows banking trojan and information-stealing malware family descended from the Gozi/ISFB codebase. It has been used for online banking fraud, credential theft, browser-based financial theft, and broader host surveillance. The family has a long criminal history, and leaked source code contributed to the emergence of multiple related banking trojan strains and variants.
Ursnif primarily targets Windows systems and is commonly delivered through phishing and malspam campaigns. Observed delivery chains include email lures with malicious attachments or links, ZIP archives containing obfuscated JavaScript downloaders, and exploitation of Microsoft Office vulnerabilities such as CVE-2017-11882. Campaigns have also used conversation hijacking, replying within legitimate email threads from compromised accounts to increase trust and improve infection rates.
Once executed, Ursnif commonly uses staged loaders and anti-analysis techniques before injecting into legitimate processes such as Explorer.exe. Reported behaviors include abuse of callback-based execution, mouse-movement-dependent decryption and execution logic, inter-thread communication through mailslots, section-mapping injection, and fallback injection into alternate Windows processes if the preferred target is unavailable. The malware has also used PowerShell-based download cradles during installation and payload retrieval.
Ursnif establishes persistence through Windows Registry Run-key modifications and related installation routines. It has been observed using deceptive naming conventions derived from legitimate system artifacts for files, folders, and Registry entries to blend into the host environment. It also performs process discovery and other host reconnaissance to support execution and collection.
Its core functionality is credential and financial-data theft. Ursnif collects extensive host and user information, including system details, browser data, cookies, credentials, clipboard contents, process information, and other application data. It supports keylogging and screenshot capture, and some variants have recorded screen activity. Stolen data is typically staged locally, compressed, and exfiltrated to command-and-control infrastructure. Ursnif has also deleted staged temporary data after exfiltration to reduce forensic visibility.
A defining capability of Ursnif is browser injection and man-in-the-browser activity against online banking and payment services. It has used WebInject-style mechanisms and HiddenVNC-related tradecraft to facilitate fraudulent transactions and abuse authenticated browser sessions. Campaigns have specifically targeted financial institutions, credit card providers, and other payment-related services, including operations focused on Japanese organizations and users.
Ursnif has appeared in broader crimeware ecosystems alongside loaders, crypters, and other malware families. It has been associated with spam and phishing operations, including campaigns linked to TA551/Hive0106, and has been observed wrapped by third-party crypters used across multiple eCrime malware families. Its longevity, modularity, and overlap with the Gozi/ISFB lineage have made Ursnif one of the more significant and adaptable banking malware families in the Windows threat landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday.
CVE-2016-7255 Classification: 0-Day Basic Description: Memory corruption in NtUserSetWindowLongPtr ... Found in the following Malware samples: Attributed to APT28 (aka Fancy Bear, Sednit). Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze | Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze
CVE-2015-2546 Classification: 1-Day Basic Description: Use-After-Free in xxxSendMessage (tagPOPUPMENU) ... Found in the following Malware samples: Ursnif, Buhtrap | Found in the following Malware samples: Ursnif, Buhtrap
CVE-2017-0001 Classification: 1-Day Basic Description: Use-After-Free in RemoveFontResourceExW ... Found in the following Malware samples: Attributed to Turla. Later used by Ursnif | Found in the following Malware samples: Ursnif, Buhtrap
CVE-2016-0040 Classification: 1-Day Basic Description: Uninitialized kernel pointer in WMIDataDevice IOControl ... Was never exploited as a 0-Day in the wild Found in the following Malware samples: Ursnif | Found in the following Malware samples: Ursnif, Buhtrap
CVE-2016-0165* Classification: 1-Day Basic Description: Use-After-Free in Win32k!xxxMNDestroyHandler ... Found in the following Malware samples: Ursnif | Found in the following Malware samples: Ursnif, Buhtrap
Spelevo Exploit Kitは2つの脆弱性(CVE-2018-8174とCVE-2018-15982)を悪用することが報告されていますが、PseudoGateによる攻撃ではCVE-2018-15982のみが観測されています。CVE-2018-15982はAdobe Flash PlayerのRCEの脆弱性です。
the seller offered two types of weaponized Microsoft Office documents (maldocs) to users: one that exploits a known vulnerability in Microsoft Office (CVE-2017-8570) and another that uses a malicious macro.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In April 2022, we observed the first use of an ITG23 crypter with the Gozi banking trojan...
In April 2022, we observed the first use of an ITG23 crypter with the Gozi banking trojan...
Maze affiliates utilize other malware and are involved with other high-end organized crimeware groups conducting systematic corporate data breaches including Zloader, Gozi and TrickBot.
The campaign pivoted from distributing the Ursnif banking trojan in early messages to later distributing Adhubllka ransomware, which encrypts files on compromised systems.
We’ve additionally seen TA564 using coronavirus emails to target Canadian users by spoofing the Public Health Agency of Canada in an attempt to deliver Ursnif. Ursnif is a common banking Trojan that can steal stored data, including passwords, from banking websites via web injections, proxies, and VNC connections.
WikiLoader has been observed installing Ursnif as a follow-on payload... The final payload in this case is the Ursnif banking trojan with GroupID “5050”.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers begin with phishing campaigns designed to acquire the email login details of targets... those behind the campaign have gained access to email login and password details they can use to extend their reach for the true aim of the campaign: distributing malware.
Valak uses a multi-stage, script-based malware that hijacks email replies and embeds malicious URLs or attachments to infect devices with fileless scripts. | Emails are harvested and used in ‘Reply Chain Attacks’ to further spread the malware with a purpose-built plugin, ‘exchgrabber’.
The Cobalt hacking group also weaponized this security flaw in one of their campaigns in late November, sending out a similarly constructed RTF file. In their previous spear-phishing campaigns, the DLL is a component of the penetration testing tool Cobalt Strike.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
the document macro generates and executes an Excel 4 macro written in Italian | Attached to the emails are malicious Microsoft Office documents containing macros. If the macros are enabled, the document will download Ursnif malware.
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI).
The attackers begin with phishing campaigns designed to acquire the email login details of targets... those behind the campaign have gained access to email login and password details they can use to extend their reach for the true aim of the campaign: distributing malware.
その後「DreamBot」は、多重にメモリ領域の確保とジャンプを繰り返す複雑なコード遷移の処理をしばらく実行し、最終的にExplorer.exeにインジェクションします。
ZwMapViewOfSectionの第二引数に相手のプロセスハンドルを指定し、自身のメモリセクションをマッピングオブジェクトとして扱うことで不正コードをリモートでインジェクションするセクションマッピングインジェクションを行います。
The attackers begin with phishing campaigns designed to acquire the email login details of targets... those behind the campaign have gained access to email login and password details they can use to extend their reach for the true aim of the campaign: distributing malware.
ダウンロードしたZIPから解凍されたJSファイルは複雑に難読化されており、復号すると以下のような可読可能なJSスクリプトの文字列(コード)が出現します。
Crypters generally operate by encrypting the pre-compiled malware payload and embedding it within a secondary binary, which we refer to as a loader.
use highly-customised phishing techniques to make it look as if the victim is the one sending messages back and forth
その後「DreamBot」は、多重にメモリ領域の確保とジャンプを繰り返す複雑なコード遷移の処理をしばらく実行し、最終的にExplorer.exeにインジェクションします。
ZwMapViewOfSectionの第二引数に相手のプロセスハンドルを指定し、自身のメモリセクションをマッピングオブジェクトとして扱うことで不正コードをリモートでインジェクションするセクションマッピングインジェクションを行います。
DeleteFileWによる自身のファイルの直接的な削除を試みますが、当然自身が起動しているため失敗し、その後、MoveFileExWにMOVEFILE_DELAY_UNTIL_REBOOTフラグを指定して実行することで、システムが次回起動した際に削除を実行するようにシステムに登録します。
The attackers begin with phishing campaigns designed to acquire the email login details of targets... those behind the campaign have gained access to email login and password details they can use to extend their reach for the true aim of the campaign: distributing malware.
The loader contains code to decrypt and execute the malicious payload
マウス操作がない(マウスが移動しない)環境では不正動作が行われません。これは主にサンドボックスなどの自動解析を考慮したものと考えられます。
Next, the malware will allocate a brand new section of memory using NtCreateSection(), which will be set to Read-Write-eXecute... the program begins to copy over the executable to the new addresses, however it skips the entire MZ header and simply copies everything from the PE header. | there are several calls to API’s, in particular VirtualProtect. VirtualProtect is responsible for changing the permissions/protection of different memory regions...
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
This file called out to command-and-control (C2) servers registered in Russia only a day prior to the launch of the campaign. | A recent obfuscation technique noted in this attack was the use of User Agents imitating Zoom and Webex to try and hide in network traffic.
938 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a next-stage payload delivered by FakeBat.
Information-stealing trojan used in malicious Word document campaigns with multi-stage script execution for payload delivery.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
Associated Analytic Story Volt Typhoon ... FIN7 ... DarkGate Malware ... Qakbot ... Gozi Malware
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.