Ursnif, also referred to in the content as Gozi, Gozi-ISFB, and Dreambot-related ISFB variants, is a common banking Trojan/backdoor in the Gozi/ISFB malware family. The content describes it as capable of stealing stored data and banking credentials, including via web injections, and supporting proxy and VNC connections; it can also update itself or install additional modules remotely. Related ISFB-family capabilities described in the content include victim fingerprinting, keylogging, form grabbing, browser replacement attacks, screen recording, email theft, file theft, SOCKS proxying, and second-stage payload delivery, with operators increasingly using it as a loader or entry point for follow-on attacks including ransomware.
Observed behavior in the content is primarily Windows-focused. Ursnif has queried the Registry for installed programs, modified the Registry as part of installation, and registered itself as a system service in the Registry for automatic execution at startup. Ursnif droppers have used COM properties to execute malware in hidden windows. The malware has also been observed manipulating TLS callbacks while injecting a child process. The content additionally notes that Ursnif droppers have used a large number of export functions, and one referenced variant employed a malicious TLS callback technique for process injection.
Infection and delivery vectors mentioned in the content include phishing and malspam ecosystems, exploit-kit delivery, and distribution by other malware. TA551 (Shathak/Gold Cabin) is described as spreading Ursnif, and TA577 is reported to have delivered Ursnif in phishing campaigns since 2020. Proofpoint tracked Ursnif in Japan-focused campaigns since at least 2017, including URLZone/Bebloh/Shiotob infections in which URLZone first infected the host and then downloaded Ursnif configured with web injects for Japanese banks; TA544 was attributed much of that Japan-focused activity. BrushaLoader was observed delivering Ursnif in Italy. Danabot has distributed Ursnif as a secondary payload, and the content also references delivery through Angler/Bedep-era malvertising and exploit-kit activity.
Targeting in the content centers on financial theft and banking fraud, with specific references to campaigns targeting Japan and Italy and to Dreambot/ISFB activity against banks in Germany and other countries. Threat-actor and ecosystem associations explicitly mentioned include TA551, TA577, TA544, TA547, and Danabot distributors, as well as broader ISFB/Dreambot criminal operations. The content also notes infrastructure observations from a June 2023 Ursnif campaign targeting Italy, where multiple remote destinations hosting Ursnif tier-1 command-and-control shared the hostname WIN-LIVFRVQFMKO.
High-confidence indicators and artifacts directly mentioned in the content include the shared hostname WIN-LIVFRVQFMKO on infrastructure tied to a June 2023 Ursnif campaign targeting Italy, and an example Ursnif C2 domain browneyandrebun[.]net associated with fileless Ursnif activity observed in November 2015.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA551, also known as Shathak or Gold Cabin, is an attacker group that is responsible for spreading a wide variety of malware families including IcedID, Valak, Ursnif and, more recently, BazarLoader.
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
Ursnif is a common banking Trojan that can: Steal stored data including passwords from banking websites via web injections, proxies and VNC connections Update itself or install modules remotely.
Since the Emotet takedown, Proofpoint observed consistent, ongoing activity from The Trick, Dridex, Qbot, IcedID, ZLoader, Ursnif, and many others in our data serving as first-stage malware payloads in attempts to enable further infections, including ransomware attacks.
The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020. More recently, they have delivered Pikabot and DarkGate malware.
It may be delivered via password-protected Zip files; Microsoft Office document attachments with malicious macros; or compressed JScript, JavaScripts, or Visual Basic scripts.
Ursnif 4779 is deployed via one of two primary methods: (1) Microsoft Excel attachments with malicious macros... or (2) steganographic images that conceal malicious PowerShell commands which install Ursnif.
((source=" WinEventLog:Microsoft-Windows-Sysmon/Operational" EventCode="1") OR (source=" WinEventLog:Security" EventCode="4688") | WHERE (Image LIKE "%reg.exe%" AND ParentImage LIKE "%cmd.exe%")
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Thread Local Storage (TLS) callback injection is a technique that entails manipulating pointers within a portable executable (PE) to redirect a process to malicious code before it reaches the code’s legitimate entry point.
One notable characteristic of TA544 is their use of steganography, which is the process of concealing code within images.
Thread Local Storage (TLS) callback injection is a technique that entails manipulating pointers within a portable executable (PE) to redirect a process to malicious code before it reaches the code’s legitimate entry point.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
It filters out security researchers and sandboxes using checks including Maxmind, task counts, task names, and recent file counts.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
the malware injects itself into the web browser and capture every HTTP POST request, which makes credential and stealing credit card easy.
After the infection, a webinject is deployed by Dreambot on the victim browsers and when that victims logs into the online banking service, credentials are intercepted to be later reused by the carder.
The main feature of the module is injecting code into the web browser that will monitor which websites the victims are visiting. If a banking website is identified, ISFB injects a small snippet of JavaScript into the online banking website to steal the login credentials.
Indicators the NetmanageIT Threat Intelligence team shared about a June 2023 Ursnif campaign targeting Italy report many remote destinations hosting Ursnif tier 1 command and controls sharing the same hostname
In the log we can see that: A client 96.57.xx.xxx Sent a web request “GET tuneappservice.org/l3k42hj56h634gkj2lk14356jk4gh23k5jl6h4/gate.php?ped=RTY3M0E4NjhDQ0I5JE1DLTEwNw” We can see here what looks like a malware callback, it’s in fact Riltok.
That’s why carders use a VNC connection to the victim's computer or a SOCKS proxy to tunnel their connection. Dreambot offers both of those techniques by design.
The service is described as a Fast flux but in reality it’s more a simple proxy system. BraZZZers rents a pool of VPSs all around the internet and uses them as proxy IPs in order to hide the real IP of a server.
with the first integration of Tor onion as available C2.
One of the very important features of Dreambot is the capability to drop a 2nd stage implant to any infected bot.
When a victim is infected by Dreambot, a VNC connection and/or a SOCKS proxy is set-up on the victim computer... he will connect directly to the victim's computer by using that VNC server and just like that he would be on the same computer at the same time with the victim, operating over a hidden desktop.
The domains involved are resolving to a list of IPs, (we observed from 1 up to more than 20 IPs per domain) that are just redirecting the traffic to the real server.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
159 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as one of the heavyweight commodity malware families from the earlier malware-analysis era.
Named malware family referenced in an associated analytic story.
Gozi is referenced as a named malware family in the associated analytic stories, but the content does not provide behavioral detail beyond the name.
Gozi is referenced as a named malware family in the associated analytic stories, but the content does not provide behavioral details beyond its mention.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.