Ursnif is a Windows banking trojan and information-stealing malware family associated with the Gozi lineage and names including Gozi ISFB and DreamBot. Historically focused on online banking credentials and financial fraud, it has also been used as a loader for subsequent compromise. Its targets include financial institutions, corporate payment services, and banking customers, with documented campaigns against Japanese banking and credit-card users.
Its capabilities include credential and cookie theft, keylogging, clipboard collection, screenshots, screen-video recording, file theft, and collection of host, application, email, and browser information. Browser injection and web injections enable man-in-the-browser attacks that modify HTTP traffic and present fraudulent credential prompts. DreamBot variants inject code into Windows processes through section mapping, establish persistence through startup configuration, and package stolen information into compressed archives for exfiltration. Anti-analysis mechanisms include mouse-movement-dependent execution and decryption, execution delays, and obfuscated inter-thread communication. Ursnif has used Tor for command and control and has propagated by copying itself to network drives and infecting shared files. Historical Gozi variants also supported domain generation algorithms and installation of a master boot record rootkit.
Distribution mechanisms include phishing and spam emails, malicious attachments and links inserted into hijacked email conversations, JavaScript downloaders, and Windows shortcut files. Campaigns have exploited Microsoft Office vulnerabilities, including CVE-2017-11882, and abused Word's embedded online-video functionality. Malvertising campaigns such as AdGholas and HookAds have delivered Ursnif through exploit kits, including Stegano and RIG. Distribution has been associated with Storm-0324, Sangria Tempest, and Hive0106, also known as TA551; the family is used by multiple criminal operators rather than a single exclusively associated actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday.
CVE-2016-7255 Classification: 0-Day Basic Description: Memory corruption in NtUserSetWindowLongPtr ... Found in the following Malware samples: Attributed to APT28 (aka Fancy Bear, Sednit). Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze | Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze
CVE-2015-2546 Classification: 1-Day Basic Description: Use-After-Free in xxxSendMessage (tagPOPUPMENU) ... Found in the following Malware samples: Ursnif, Buhtrap | Found in the following Malware samples: Ursnif, Buhtrap
CVE-2017-0001 Classification: 1-Day Basic Description: Use-After-Free in RemoveFontResourceExW ... Found in the following Malware samples: Attributed to Turla. Later used by Ursnif | Found in the following Malware samples: Ursnif, Buhtrap
CVE-2016-0040 Classification: 1-Day Basic Description: Uninitialized kernel pointer in WMIDataDevice IOControl ... Was never exploited as a 0-Day in the wild Found in the following Malware samples: Ursnif | Found in the following Malware samples: Ursnif, Buhtrap
CVE-2016-0165* Classification: 1-Day Basic Description: Use-After-Free in Win32k!xxxMNDestroyHandler ... Found in the following Malware samples: Ursnif | Found in the following Malware samples: Ursnif, Buhtrap
Spelevo Exploit Kitは2つの脆弱性(CVE-2018-8174とCVE-2018-15982)を悪用することが報告されていますが、PseudoGateによる攻撃ではCVE-2018-15982のみが観測されています。CVE-2018-15982はAdobe Flash PlayerのRCEの脆弱性です。
the seller offered two types of weaponized Microsoft Office documents (maldocs) to users: one that exploits a known vulnerability in Microsoft Office (CVE-2017-8570) and another that uses a malicious macro.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The threat actors Sangria Tempest and Storm-0324 previously had been associated with the distribution of the Gozi InfoStealer.”
“The threat actors Sangria Tempest and Storm-0324 previously had been associated with the distribution of the Gozi InfoStealer.”
In April 2022, we observed the first use of an ITG23 crypter with the Gozi banking trojan...
In April 2022, we observed the first use of an ITG23 crypter with the Gozi banking trojan...
Maze affiliates utilize other malware and are involved with other high-end organized crimeware groups conducting systematic corporate data breaches including Zloader, Gozi and TrickBot.
The campaign pivoted from distributing the Ursnif banking trojan in early messages to later distributing Adhubllka ransomware, which encrypts files on compromised systems.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
939 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer mentioned as a historical payload distributed by Storm-0324 and Sangria Tempest. Gozi V3 also appears in the list of Storm-0324's previous payloads; the article does not analyze its operation.
Mentioned as a banking Trojan that attackers repurposed for other malicious activities.
Referenced as a next-stage payload delivered by FakeBat.
Information-stealing trojan used in malicious Word document campaigns with multi-stage script execution for payload delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.