Group 53 is a financially motivated cybercrime cluster associated with ISFB, also known as Ursnif or Gozi, a banking trojan used to steal financial information. The cluster has been observed using malicious Microsoft Word documents with embedded macros for initial access, followed by PowerShell-based retrieval of a first-stage executable. Its infection chain includes self-injection, multi-stage unpacking, in-memory decryption, dynamic API resolution, and transfer to a second-stage loader DLL. The group’s tooling demonstrates mature loader engineering and anti-analysis tradecraft. Observed samples decrypt strings from the .bss section using a date-derived rotation/XOR scheme, resolve APIs through CRC-based hashing, install vectored exception handlers, parse embedded joined-resource structures, decompress payload data with APLib, and prepare subsequent stages in memory using native Windows APIs. Later-stage components derive host-specific identifiers from system attributes including SID, username, computer name, and CPUID output, then use those values in command-and-control communications. Group 53 has used encrypted command-and-control traffic protected with Serpent and RSA, with additional request obfuscation layered over encoded data. The malware has been observed using COM and Internet Explorer components for network communications, retrieving architecture-specific payloads and a PowerShell script from command-and-control infrastructure. Follow-on activity includes storing components in the registry, launching hidden PowerShell through WMIC, APC-related execution, injection into explorer.exe, and deletion of the original malware to reduce forensic visibility. Known aliases directly supported here are limited to Group 53. The cluster is associated with ISFB/Ursnif/Gozi operations oriented toward theft of financial information rather than espionage or disruptive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated threat actor using the ISFB banking trojan infection chain. The analyzed second-stage loader parses embedded configuration and RSA material, communicates with C2 via Internet Explorer COM interfaces, retrieves 32-bit and 64-bit payloads plus a PowerShell script, stores components in the registry, and uses WMIC/PowerShell with APC-style injection to launch the next stage in explorer.exe while deleting the original file.
An ISFB v2 activity cluster associated with banking trojan campaigns for financial theft. In this sample, the group uses malicious Word documents with embedded macros that launch Base64-encoded PowerShell to download the first-stage executable, and is noted for reusing the default encryption key across campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.