Researchers documented multiple Ursnif campaigns in which the malware evolved beyond a traditional banking trojan into a stealthy loader, reconnaissance tool, and credential theft platform. In North America and Europe, attackers hijacked existing email threads and sent links to password-protected ZIP archives containing obfuscated JavaScript, while other operations used phishing lures themed as Italian courier and energy companies with malicious Office documents. The malware chain commonly relied on Windows scripting and LOLBins such as wscript and regsvr32, staged DLL loading, anti-analysis tricks, and geofencing or locale checks to reduce detection and limit infections to intended victims.
The activity was tied to sustained, targeted operations including campaigns attributed to TA544 against Italian organizations and a separate LOLSnif variant observed from 2019 into 2020. Analysts reported that the malware reused infrastructure, bypassed local proxies through COM interfaces and Internet Explorer automation, and used WMI and broken PE headers to frustrate defenders. In several intrusions, Ursnif infections led to follow-on payloads including Cobalt Strike Beacon, TeamViewer/TVRat, and a VNC-related module, showing that the campaigns supported both credential theft and broader post-compromise remote access.

Get the infrastructure and lures behind it.
12 events from the most recent confirmed update back to the earliest known activity.
In 2021, Proofpoint observed nearly 20 notable TA544 campaigns and almost half a million messages targeting Italian organizations with Ursnif, including lures impersonating courier and energy companies.
Between January and August 2021, observed Ursnif campaigns impacting Italian organizations exceeded the total number of such campaigns seen in all of 2020.
Proofpoint said Emotet activity targeting Italy disappeared after the January 2021 disruption of the Emotet botnet, preceding increased Ursnif activity in the region.
The JavaScript file used in the LOLSnif campaign was first submitted to VirusTotal on 2020-04-07 and initially had a very low detection rate.
A LOLSnif campaign began on 2020-04-07 with spam emails carrying encrypted ZIP archives and passwords in the message body.
The LOLSnif Ursnif variant was first publicly mentioned in August 2019 before gaining momentum later in 2019 and early 2020.
The LOLSnif campaigns gained momentum in autumn and winter 2019/2020 as the repurposed Ursnif variant was used in targeted cybercrime operations.
Proofpoint stated it has tracked the cybercriminal group TA544 since 2017 as an actor distributing banking malware and other payloads.
The Ursnif source code was leaked in 2014, making it broadly available online and enabling later repurposing of the malware family.
Some Ursnif infections progressed beyond initial beaconing and, after about 24 hours, received additional modules including a VNC-related component, Cobalt Strike beacons, and TVRat using TeamViewer.
As of April 22, the campaign operators moved infrastructure from 8.208.90.28 to 47.241.106.208 after initially using 16 domains pointed at the earlier IP.
A growing Ursnif campaign began around April 6, targeting entities across North America and Europe using compromised email accounts and malicious Google Drive links.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourcetelekom.com
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.