Researchers tracking Ursnif uncovered a wider command-and-control footprint tied to the long-running banking trojan and its role in later-stage ransomware intrusions. Bridewell identified a distinctive SSL certificate pattern and related network traits that revealed 72 additional servers, then used a second hunt rule to find 7 more previously missed systems. Several of the discovered C2 nodes had gone unreported or were poorly detected by security tools, with an average VirusTotal detection score of 4.78, and the infrastructure was concentrated in Germany, the Netherlands, and Russia across providers including servinga GmbH, Datasource AG, and GleSYS AB.
The findings reinforce Ursnif's evolution from a banking trojan into a broader intrusion enabler used for credential theft, data exfiltration, and ransomware access. Earlier reporting linked Ursnif to campaigns against more than 100 Italian banks, theft of over 1,700 credential sets from one payment processor, and phishing-led infections targeting organizations in Italy and the United States. Bridewell also tied current activity to malicious LibreOffice installers, DLL payloads, and domains including gameindikdowd[.]ru, while noting overlap with intrusions associated with the Royal ransomware group.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
One of the Ursnif command-and-control IPs later highlighted as unreported, 31.214.157[.]31, had a Shodan scan date of 2023-04-30. Bridewell noted it had a low VirusTotal detection rate of 2/87.
CISA stated in March 2023 that the Royal ransomware group uses malware tools and derivatives such as Ursnif/Gozi for data aggregation and exfiltration.
Shodan history showed that IP address 185.189.151[.]38 used an SSL certificate matching Bridewell's Ursnif hunt rule in January 2023. The server was linked to the MSICBE.tmp sample, which was configured to beacon to that IP.
Royal ransomware became a prominent threat to organizations globally starting in September 2022. The Bridewell report frames Ursnif as a malware family used during Royal ransomware intrusions.
Darktrace documented a 2020 Ursnif campaign in which a phishing email sent to a US bank employee led to execution of a malicious file disguised as a .cab archive. The malware contacted command-and-control servers registered in Russia one day before the campaign began, and those IPs were not blacklisted at the time.
The Ursnif Trojan was first discovered in 2007 and initially emerged as a simple banking Trojan before later evolving into a more sophisticated information stealer.
Researchers built a second hunt rule using HTTP header information pivoted from 176.10.111[.]167. The rule returned 55 servers and, after deduplication, surfaced 7 servers not caught by the initial SSL-based hunt.
Using a distinctive SSL certificate pattern and other fingerprintable features, researchers identified 72 additional servers of interest linked to Ursnif infrastructure. The analysis also found several Ursnif C2 servers were unreported or poorly detected by security vendors.
Avast reported that Ursnif had been used in attacks against at least 100 banks in Italy, stealing credentials and financial data. In one case, an unnamed payment processor had more than 1,700 credential sets stolen, and Avast shared findings with identifiable victim banks and CERTFin Italy.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 78 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.