Ursnif is a long-running banking malware family also known as Gozi, Dreambot, and ISFB. It is primarily associated with financially motivated cybercrime and has been distributed through email-driven malware campaigns. Ursnif is used to compromise victim systems and support follow-on fraud and data theft operations. Public reporting has linked Ursnif infrastructure and operators to adversary-in-the-middle account compromise activity, indicating continued operational evolution beyond traditional banking-trojan use cases. Ursnif is commonly discussed alongside other major crimeware families such as Dridex, QakBot, Emotet, and IcedID because it has appeared in overlapping spam and malware-delivery ecosystems. High-confidence evidence in the available material supports Ursnif’s role in email-based initial compromise and broader credential-focused criminal operations, but does not support a precise national attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with DGA-like domains on the same shared infrastructure and delivered through email campaigns.
Mentioned only as another malware family using the same packer; not part of the main activity discussed.
Banking malware operators referenced for using APC-based injection/execution as part of campaigns (noted as privilege escalation in the text).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.