Dreambot is a widely used variant of the Ursnif/Gozi ISFB banking trojan and is best understood as malware and an associated criminal operation rather than a clearly delineated named intrusion set. It has been active since at least 2014 and has been distributed through large-scale malspam, malicious links, exploit kits, malvertising, and secondary-payload delivery chains. Dreambot has been described as being offered as a crime-as-a-service capability in some campaigns. Its primary activity is financial cybercrime. Dreambot is designed to steal banking and payment-related information, including credentials and other browser- and email-derived data, and to support fraudulent transactions through web injection and related post-compromise manipulation. Observed targeting has included banks, credit card companies, and cryptocurrency exchanges, with especially extensive targeting in Japan. Campaigns have also targeted users in Australia, Italy, Switzerland, the United Kingdom, the United States, Poland, and Canada. Operationally, Dreambot campaigns have used multiple delivery routes, including spam bot infrastructure, compromised email accounts, reply-chain lures, malicious document attachments, JavaScript and VBS downloaders, and exploit-kit-based infection chains. In Japan-focused activity, Dreambot-linked operations were distinguished from a separate Ursnif cluster by their reliance on URL-based delivery, broader financial targeting, and different command-and-control infrastructure. Those campaigns also shifted tactics over time, including later use of Emotet for delivery. Technically, Dreambot has evolved beyond standard Ursnif functionality by incorporating Tor-based command-and-control communications and peer-to-peer networking in some versions, complicating detection and disruption. It has also used domain generation and fast-flux-style infrastructure, along with obfuscation and encrypted configuration handling. As a banking trojan family with multiple forks and aliases, Dreambot is closely associated with the broader Ursnif, Gozi, ISFB, Snifula, and Papras lineage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dreambot is a banking Trojan, a variant of Ursnif/Gozi ISFB, actively developed and distributed via exploit kits and email campaigns. It is known for stealing banking credentials and other sensitive information, and features advanced capabilities such as Tor-based C2 communication and peer-to-peer (P2P) networking.
Crime-as-a-Service Ursnif operation used by Group-B in campaigns targeting Japan, delivering banking-trojan functionality against banks, credit card companies, and cryptocurrency exchanges via malicious URLs, compromised email accounts, reply-chain lures, and later Emotet as a delivery route.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.