The Gozi/Ursnif/ISFB banking trojan remained an active cybercrime threat across Europe and Japan, spreading mainly through targeted malspam and phishing emails carrying weaponized Word, XLS, ZIP, JavaScript, HTA, and macro-enabled attachments. Multiple campaigns used staged infection chains involving VBA macros, PowerShell, rundll32, HTA downloaders, and side-loaded DLLs, with distribution tied in some cases to the Dark Cloud botnet and other spam infrastructure. Researchers also observed related delivery through Shiotob downloaders and compromised web servers, with operators rotating domains, IPs, and lure content to reduce detection while targeting both retail and corporate banking users.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
Qualys documented two observed Ursnif infection chains: one using a malicious XLS attachment with VBA macros and another using a ZIP archive containing an HTA file. The analysis also detailed parent PID spoofing, in-memory unpacking, encrypted HTTP C2 traffic, and a final payload that acted as a keylogger and browser data stealer.
Cleafy described how Gozi infections retrieved a second-stage fraud toolkit including web-injects, hVNC, and SOCKS modules used for banking fraud. The observed configurations targeted more than 50 financial institutions, primarily in Italy and Germany, with RATBANK as the main web-inject kit and 'tables' used in some German-targeting cases.
FortiGuard Labs reported a phishing campaign targeting Windows users in Italy that used an Italian-language payment-reminder lure and a malicious Word document to deliver a fresh Ursnif variant. The analysis detailed macro-based DLL download and RegSvr32 execution, in-memory unpacking of the Ursnif core, IE ActiveX-based C2 communications, and identified gstatistics[.]co as the real command-and-control domain.
Qualys stated that Ursnif became one of the top ten most prolific malware families in 2020. The malware was described as a widespread banking trojan distributed primarily through spear-phishing emails.
A JSAC/JPCERT presentation analyzing Japanese Ursnif malspam activity from 2016 onward concluded that two distinct threat groups operated against Japan. The researchers differentiated Group-A and Group-B by their delivery methods, malware chains, infrastructure, and targeting, including XLS+Bebloh+Ursnif activity versus URL/JavaScript-led Dreambot-Ursnif infections.
FortiGuard Labs reported an actively spreading Ursnif campaign using malicious Word documents with VBA macros and obfuscated PowerShell to download and execute a new Ursnif variant. The analysis detailed in-memory unpacking, anti-analysis features, COM-based Internet Explorer exfiltration via IWebBrowser.Navigate(), and published C2 hosts, hashes, and a download URL as indicators of compromise.
VMRay published a behavioral analysis of a single Ursnif sample, describing modules that stole data from Outlook and Internet Explorer and likely targeted Thunderbird as well. The report also detailed host-enumeration via native Windows utilities and explained that stolen data was cached to disk, compressed into CAB archives, and uploaded for exfiltration.
A reverse-engineering post analyzed an ISFB/Ursnif/Gozi v2.14.60 sample attributed to "Group 53," describing a Word-macro and PowerShell delivery chain into a first-stage executable that self-injected and unpacked a second-stage DLL. The writeup detailed date-derived ROR/XOR string decryption, CRC-32/JAMCRC API hashing, anti-analysis behavior, and published sample hashes for the unpacked components.
Cisco Talos reported a fresh Ursnif infection chain delivered through malicious Word documents with VBA macros that extracted hidden PowerShell, downloaded an executable, and used staged PowerShell plus APC injection to load a DLL in memory. The report also published indicators of compromise including malicious document hashes, dropped filenames, and command-and-control domains tied to the campaign.
A reverse-engineering writeup analyzed a second-stage ISFB loader that used Microsoft COM and an Internet Explorer COM object to communicate with command-and-control servers without DLL injection or process hollowing. The sample navigated to a C2 URL, waited for page load completion, and extracted response text from the HTML body for decryption and parsing.
Cisco Talos reported that the analyzed Gozi ISFB campaigns used the Dark Cloud botnet for distribution and tied related infrastructure to Nymaim activity, spam, scams, and carding operations. The report also noted that more than 100 malicious Word documents from the campaign had been analyzed.
SANS ISC analyzed two malicious spam emails with Word attachments whose macros infected a Windows host with Gozi-ISFB. One chain led to probable Nymaim, while the other led to an unidentified payload side-loaded through a malicious WINMM.dll.
Cleafy cited FireEye research published in 2018 that described the 'tables' web-inject kit. Cleafy later observed less-common Gozi configurations using this kit alongside RATBANK.
Palo Alto Networks documented a two-part distribution network made up of a spam botnet and compromised web servers that delivered Ursnif and other malware. The campaign heavily targeted Japan and several European countries and had been active for more than a year against Japan.
Cisco Talos reported ongoing low-volume, targeted malicious spam campaigns distributing Gozi ISFB from late 2017 into 2018. The campaigns used individualized Word documents, obfuscated VBA macros, HTA and JavaScript stages, and PowerShell to retrieve payloads.
Palo Alto Networks reported that the latest attachment observed in January 2017 was a JavaScript downloader that fetched Ursnif from a remote site and executed it on the victim machine. This reflected an evolution in the campaign's attachment-based delivery chain.
An investigation of 200 Japanese IP addresses associated with the campaign found they sent 250 unique malware samples across 268,000 emails in 2016. Most of the malware distributed from those IPs was classified as banking trojans or downloader trojans.
Throughout 2016, Palo Alto Networks observed millions of malicious emails sent to Japanese targets, most written in Japanese. The campaign used localized lures and attachments to distribute banking trojans and downloader trojans.
Palo Alto Networks reported that the adversary had used Shiotob mainly to download main payloads such as Ursnif since at least mid-2016, rather than primarily for credential theft. Shiotob contacted command-and-control servers over HTTPS and installed follow-on malware based on received commands.
Palo Alto Networks found more than 200 malicious files on 74 compromised servers used by the Ursnif distribution network between April 2015 and January 2017. The infrastructure supported spam-delivered banking trojans and downloader payloads across multiple countries.
Secureworks reported that Trojan.Gozi infected thousands of systems in late 2006 and early 2007, with one variant compromising more than 5,200 hosts and over 10,000 user accounts across financial, retail, healthcare, and government services. The malware intercepted HTTP and SSL/TLS-protected browser sessions and was estimated to have stolen data worth at least $2 million.
The Tokyo Metropolitan Police Department and the Japan Cybercrime Control Center issued public warnings about the malicious email campaign distributing Ursnif-related malware. The warnings were tied to the spam-driven activity targeting Japan.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourceblog.qualys.com
Open sourcecleafy.com
Open sourcefortinet.com
Open sourceblog.talosintelligence.com
Open sourceisc.sans.edu
Open sourceresearchcenter.paloaltonetworks.com
Open sourcejsac.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.