S0386: Ursnif
Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]
Security context for executives and security teams
Ursnif matters because ATT&CK describes it as a Windows banking trojan associated primarily with data theft, with variants that can include backdoor, spyware, and file-injection capabilities. For leaders, the practical issue is not just “malware detection”; it is whether email-delivered or exploit-kit-delivered malware can collect credentials and local data, communicate over web traffic, stage and exfiltrate information, and hide through obfuscation or process injection before responders have enough evidence to scope the incident.
Executive priority
Prioritize Ursnif-related readiness where Windows endpoints, email-based delivery risk, credential theft, and sensitive local data exposure would create business disruption or audit concern. Executives should ask whether the organization can prove coverage across prevention, endpoint telemetry, web/C2 monitoring, credential-access investigation, and incident response scoping. Because TA551 is documented as using Ursnif and is described as financially motivated and email-focused, security leaders should also validate phishing resilience and malware triage workflows without assuming current exposure or activity.
Technical view
SOC and IR teams should validate Windows-focused visibility across the behaviors ATT&CK relates to Ursnif: registry and service discovery, process and system discovery, PowerShell and Visual Basic execution, WMI abuse, process injection including TLS callback injection and process hollowing, credential API hooking, local data collection/staging, web-protocol C2, proxy or multi-hop proxy use, ingress tool transfer, exfiltration over C2, file deletion, removable media replication, and tainted shared content. MITRE provides no official detection text for this malware object, so detections should be behavior-led using the related techniques rather than relying only on static malware names or signatures.
Likely telemetry
- Windows endpoint process creation and command-line telemetry, including PowerShell, Visual Basic, WMI, service-query, process-query, and registry-query activity
- Endpoint detection telemetry for process injection, suspicious memory behavior, process hollowing indicators, and TLS callback-related execution where available
- Windows Registry access and modification events relevant to discovery, masquerading, and persistence-like investigation context
- File system telemetry for local data staging, encoded or encrypted files, dropped tools, deletion activity, and files placed in trusted-looking paths or shared locations
- Credential-access telemetry where available, including API hooking or suspicious access to authentication-related processes/functions
Detection direction
- Build coverage around ATT&CK behaviors related to Ursnif rather than the malware name alone, because the object notes multiple variants and components with a wide variety of behaviors.
- Correlate email delivery indicators with post-delivery Windows execution, especially script execution, WMI activity, registry/service/process discovery, and unexpected child processes from user-facing applications.
- Tune for suspicious discovery sequences on Windows endpoints, but account for administrative tools and software inventory products that may legitimately query services, processes, registry keys, and system information.
- Hunt for process-injection and process-hollowing patterns paired with outbound web traffic, file staging, or credential-access signals; these combinations are more useful than any single noisy event.
- Validate network monitoring for web-protocol C2 and proxy behavior, recognizing that malicious traffic may blend with normal HTTP/S activity and that multi-hop proxying can obscure infrastructure attribution.
Mitigation priorities
- Start with phishing and malicious-link controls, attachment detonation, user reporting, and email investigation workflows because ATT&CK describes Ursnif distribution through spearphishing attachments and malicious links.
- Harden Windows endpoints against script, WMI, and unauthorized process activity using least privilege, application control, and script-execution governance appropriate to the business environment.
- Strengthen credential protection and monitoring because related behavior includes Credential API Hooking and the malware is associated with data theft.
- Ensure EDR and centralized logging capture process, registry, file, memory-behavior, and network evidence needed for scoping, not just blocking alerts.
- Segment and monitor sensitive data locations, shared storage, and removable-media pathways where related techniques such as local data staging, tainted shared content, and removable-media replication are relevant.
Additional notes and limits
This take is based only on the supplied ATT&CK S0386 fields, references, and relationships. The strongest defensive value comes from mapping Ursnif to its related behaviors: Windows execution and discovery, credential collection, evasion, C2 over web protocols, staging, and exfiltration. The official object does not specify tactics directly and does not provide official detection guidance, so local control validation should be technique-based.
The supplied ATT&CK object does not include official detection text, aliases, labels, or direct indicators of compromise. It identifies Windows as the platform for Ursnif, while some related techniques list broader platforms; this summary treats Ursnif readiness as Windows-centered and uses non-Windows platform references only as technique context. No claim is made about active exploitation, current campaigns, customer exposure, or guaranteed detection.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Ursnif
Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
Groups, software, and campaigns
G0127: TA551
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.5 | Current bundle | 01b386732b43… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]NJCCIC Ursnif Sept 2016
NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
Open source URL - [2]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [3]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [4]TrendMicro PE_URSNIF.A2
Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.
Open source URL - [5]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [6]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [7]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [8]TrendMicro Ursnif File Dec 2014
Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.
Open source URL - [9]Cybereason Valak May 2020
Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.
Open source URL - [10]Unit 42 Valak July 2020
Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.
Open source URL - [11]Unit 42 TA551 Jan 2021
Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.
Open source URL - [12]Secureworks GOLD CABIN
Secureworks. (n.d.). GOLD CABIN Threat Profile. Retrieved March 17, 2021.
Open source URL - [13]Dreambot
(Citation: NJCCIC Ursnif Sept 2016)(Citation: ProofPoint Ursnif Aug 2016)
- [14]Dreambot
(Citation: NJCCIC Ursnif Sept 2016)(Citation: ProofPoint Ursnif Aug 2016)
- [15]Dreambot
(Citation: NJCCIC Ursnif Sept 2016)(Citation: ProofPoint Ursnif Aug 2016)
- [16]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [17]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [18]Gozi-ISFB
(Citation: FireEye Ursnif Nov 2017)(Citation: ProofPoint Ursnif Aug 2016)
- [19]Gozi-ISFB
(Citation: FireEye Ursnif Nov 2017)(Citation: ProofPoint Ursnif Aug 2016)
- [20]Gozi-ISFB
(Citation: FireEye Ursnif Nov 2017)(Citation: ProofPoint Ursnif Aug 2016)
- [21]NJCCIC Ursnif Sept 2016
NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
Open source URL - [22]NJCCIC Ursnif Sept 2016
NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
Open source URL - [23]PE_URSNIF
(Citation: TrendMicro Ursnif Mar 2015)
- [24]PE_URSNIF
(Citation: TrendMicro Ursnif Mar 2015)
- [25]PE_URSNIF
(Citation: TrendMicro Ursnif Mar 2015)
- [26]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [27]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [28]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [29]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [30]Ursnif
(Citation: NJCCIC Ursnif Sept 2016)
- [31]Ursnif
(Citation: NJCCIC Ursnif Sept 2016)
- [32]Ursnif
(Citation: NJCCIC Ursnif Sept 2016)
- [33]mitre-attackS0386Open source URL
- [34]mitre-attackS0386Open source URL
- [35]mitre-attackS0386Open source URL
- [36]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [37]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [38]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [39]TrendMicro PE_URSNIF.A2
Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.
Open source URL - [40]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [41]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [42]TrendMicro PE_URSNIF.A2
Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.
Open source URL - [43]TrendMicro PE_URSNIF.A2
Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.
Open source URL - [44]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [45]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [46]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [47]NJCCIC Ursnif Sept 2016
NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
Open source URL - [48]NJCCIC Ursnif Sept 2016
NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
Open source URL - [49]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [50]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [51]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [52]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [53]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [54]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [55]TrendMicro Ursnif File Dec 2014
Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.
Open source URL - [56]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [57]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [58]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [59]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [60]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [61]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [62]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [63]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [64]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [65]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [66]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [67]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [68]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [69]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [70]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [71]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [72]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [73]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [74]TrendMicro PE_URSNIF.A2
Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.
Open source URL - [75]TrendMicro PE_URSNIF.A2
Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.
Open source URL - [76]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [77]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [78]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [79]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [80]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [81]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [82]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [83]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [84]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [85]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [86]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [87]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [88]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [89]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [90]TrendMicro PE_URSNIF.A2
Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.
Open source URL - [91]TrendMicro PE_URSNIF.A2
Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.
Open source URL - [92]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [93]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [94]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [95]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [96]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [97]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [98]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [99]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [100]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [101]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [102]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [103]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [104]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [105]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [106]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [107]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [108]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [109]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [110]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [111]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [112]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [113]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [114]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [115]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [116]NJCCIC Ursnif Sept 2016
NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
Open source URL - [117]NJCCIC Ursnif Sept 2016
NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
Open source URL - [118]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [119]ProofPoint Ursnif Aug 2016
Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Open source URL - [120]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [121]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL - [122]FireEye Ursnif Nov 2017
Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Open source URL - [123]TrendMicro BKDR_URSNIF.SM
Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Open source URL - [124]TrendMicro Ursnif File Dec 2014
Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.
Open source URL - [125]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [126]TrendMicro Ursnif File Dec 2014
Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.
Open source URL - [127]TrendMicro Ursnif Mar 2015
Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Open source URL - [128]Bromium Ursnif Mar 2017
Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
