LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0386: Ursnif

Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]

EnterpriseS0386MalwareObject v1.5Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Ursnif matters because ATT&CK describes it as a Windows banking trojan associated primarily with data theft, with variants that can include backdoor, spyware, and file-injection capabilities. For leaders, the practical issue is not just “malware detection”; it is whether email-delivered or exploit-kit-delivered malware can collect credentials and local data, communicate over web traffic, stage and exfiltrate information, and hide through obfuscation or process injection before responders have enough evidence to scope the incident.

Executive priority

Prioritize Ursnif-related readiness where Windows endpoints, email-based delivery risk, credential theft, and sensitive local data exposure would create business disruption or audit concern. Executives should ask whether the organization can prove coverage across prevention, endpoint telemetry, web/C2 monitoring, credential-access investigation, and incident response scoping. Because TA551 is documented as using Ursnif and is described as financially motivated and email-focused, security leaders should also validate phishing resilience and malware triage workflows without assuming current exposure or activity.

Technical view

SOC and IR teams should validate Windows-focused visibility across the behaviors ATT&CK relates to Ursnif: registry and service discovery, process and system discovery, PowerShell and Visual Basic execution, WMI abuse, process injection including TLS callback injection and process hollowing, credential API hooking, local data collection/staging, web-protocol C2, proxy or multi-hop proxy use, ingress tool transfer, exfiltration over C2, file deletion, removable media replication, and tainted shared content. MITRE provides no official detection text for this malware object, so detections should be behavior-led using the related techniques rather than relying only on static malware names or signatures.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry, including PowerShell, Visual Basic, WMI, service-query, process-query, and registry-query activity
  • Endpoint detection telemetry for process injection, suspicious memory behavior, process hollowing indicators, and TLS callback-related execution where available
  • Windows Registry access and modification events relevant to discovery, masquerading, and persistence-like investigation context
  • File system telemetry for local data staging, encoded or encrypted files, dropped tools, deletion activity, and files placed in trusted-looking paths or shared locations
  • Credential-access telemetry where available, including API hooking or suspicious access to authentication-related processes/functions

Detection direction

  • Build coverage around ATT&CK behaviors related to Ursnif rather than the malware name alone, because the object notes multiple variants and components with a wide variety of behaviors.
  • Correlate email delivery indicators with post-delivery Windows execution, especially script execution, WMI activity, registry/service/process discovery, and unexpected child processes from user-facing applications.
  • Tune for suspicious discovery sequences on Windows endpoints, but account for administrative tools and software inventory products that may legitimately query services, processes, registry keys, and system information.
  • Hunt for process-injection and process-hollowing patterns paired with outbound web traffic, file staging, or credential-access signals; these combinations are more useful than any single noisy event.
  • Validate network monitoring for web-protocol C2 and proxy behavior, recognizing that malicious traffic may blend with normal HTTP/S activity and that multi-hop proxying can obscure infrastructure attribution.

Mitigation priorities

  • Start with phishing and malicious-link controls, attachment detonation, user reporting, and email investigation workflows because ATT&CK describes Ursnif distribution through spearphishing attachments and malicious links.
  • Harden Windows endpoints against script, WMI, and unauthorized process activity using least privilege, application control, and script-execution governance appropriate to the business environment.
  • Strengthen credential protection and monitoring because related behavior includes Credential API Hooking and the malware is associated with data theft.
  • Ensure EDR and centralized logging capture process, registry, file, memory-behavior, and network evidence needed for scoping, not just blocking alerts.
  • Segment and monitor sensitive data locations, shared storage, and removable-media pathways where related techniques such as local data staging, tainted shared content, and removable-media replication are relevant.
Additional notes and limits

This take is based only on the supplied ATT&CK S0386 fields, references, and relationships. The strongest defensive value comes from mapping Ursnif to its related behaviors: Windows execution and discovery, credential collection, evasion, C2 over web protocols, staging, and exfiltration. The official object does not specify tactics directly and does not provide official detection guidance, so local control validation should be technique-based.

The supplied ATT&CK object does not include official detection text, aliases, labels, or direct indicators of compromise. It identifies Windows as the platform for Ursnif, while some related techniques list broader platforms; this summary treats Ursnif readiness as Windows-centered and uses non-Windows platform references only as technique context. No claim is made about active exploitation, current campaigns, customer exposure, or guaranteed detection.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Ursnif

Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

35 rows
DomainIDNameRelationship / procedure
EnterpriseT1007System Service Discovery

Ursnif has gathered information about running services.[3]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Ursnif has used Registry Run keys to establish automatic execution at system startup.[4][5]

EnterpriseT1105Ingress Tool Transfer

Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads.[4][5]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk.[2] Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands.[6]

EnterpriseT1090.003Multi-hop ProxySub-technique

Ursnif has used Tor for C2.[1][2]

EnterpriseT1074.001Local Data StagingSub-technique

Ursnif has used tmp files to stage gathered information.[3]

EnterpriseT1106Native API

Ursnif has used CreateProcessW to create child processes.[7]

EnterpriseT1497.003Time Based ChecksSub-technique

Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools.[8]

EnterpriseT1559.001Component Object ModelSub-technique

Ursnif droppers have used COM objects to execute the malware's full executable payload.[6]

EnterpriseT1056.004Credential API HookingSub-technique

Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers.[3]

EnterpriseT1057Process Discovery

Ursnif has gathered information about running processes.[3][5]

EnterpriseT1041Exfiltration Over C2 Channel

Ursnif has used HTTP POSTs to exfil gathered information.[3][7][2]

EnterpriseT1132Data Encoding

Ursnif has used encoded data in HTTP URLs for C2.[2]

EnterpriseT1055.005Thread Local StorageSub-technique

Ursnif has injected code into target processes via thread local storage callbacks.[3][4][7]

EnterpriseT1140Deobfuscate/Decode Files or Information

Ursnif has used crypto key information stored in the Registry to decrypt Tor clients dropped to disk.[2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names.[3]

EnterpriseT1005Data from Local System

Ursnif has collected files from victim machines, including certificates and cookies.[5]

EnterpriseT1027.010Command ObfuscationSub-technique

Ursnif droppers execute base64 encoded PowerShell commands.[6]

EnterpriseT1113Screen Capture

Ursnif has used hooked APIs to take screenshots.[3][5]

EnterpriseT1543.003Windows ServiceSub-technique

Ursnif has registered itself as a system service in the Registry for automatic execution at system startup.[4]

EnterpriseT1059.001PowerShellSub-technique

Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload.[6]

EnterpriseT1071.001Web ProtocolsSub-technique

Ursnif has used HTTPS for C2.[3][7][2]

EnterpriseT1070.004File DeletionSub-technique

Ursnif has deleted data staged in tmp files after exfiltration.[3]

EnterpriseT1012Query Registry

Ursnif has used Reg to query the Registry for installed programs.[3][5]

EnterpriseT1112Modify Registry

Ursnif has used Registry modifications as part of its installation routine.[5][2]

EnterpriseT1568.002Domain Generation AlgorithmsSub-technique

Ursnif has used a DGA to generate domain names for C2.[2]

EnterpriseT1059.005Visual BasicSub-technique

Ursnif droppers have used VBA macros to download and execute the malware's full executable payload.[6]

EnterpriseT1082System Information Discovery

Ursnif has used Systeminfo to gather system information.[3]

EnterpriseT1090Proxy

Ursnif has used a peer-to-peer (P2P) network for C2.[1][2]

EnterpriseT1047Windows Management Instrumentation

Ursnif droppers have used WMI classes to execute PowerShell commands.[6]

EnterpriseT1055.012Process HollowingSub-technique

Ursnif has used process hollowing to inject into child processes.[7]

EnterpriseT1185Browser Session Hijacking

Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords).[5]

EnterpriseT1080Taint Shared Content

Ursnif has copied itself to and infected files in network drives for propagation.[3][8]

EnterpriseT1091Replication Through Removable Media

Ursnif has copied itself to and infected removable drives for propagation.[3][8]

EnterpriseT1564.003Hidden WindowSub-technique

Ursnif droppers have used COM properties to execute malware in hidden windows.[6]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0127: TA551

TA551 is a financially-motivated threat group that has been active since at least 2018. [1] The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns. [2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.5
Created
Modified
Raw hash
01b386732b43a84b...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.5Current bundle01b386732b43…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    NJCCIC Ursnif Sept 2016

    NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.

    Open source URL
  2. [2]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  3. [3]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  4. [4]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  5. [5]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  6. [6]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  7. [7]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  8. [8]
    TrendMicro Ursnif File Dec 2014

    Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.

    Open source URL
  9. [9]
    Cybereason Valak May 2020

    Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.

    Open source URL
  10. [10]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  11. [11]
    Unit 42 TA551 Jan 2021

    Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.

    Open source URL
  12. [12]
    Secureworks GOLD CABIN

    Secureworks. (n.d.). GOLD CABIN Threat Profile. Retrieved March 17, 2021.

    Open source URL
  13. [13]
    Dreambot

    (Citation: NJCCIC Ursnif Sept 2016)(Citation: ProofPoint Ursnif Aug 2016)

  14. [14]
    Dreambot

    (Citation: NJCCIC Ursnif Sept 2016)(Citation: ProofPoint Ursnif Aug 2016)

  15. [15]
    Dreambot

    (Citation: NJCCIC Ursnif Sept 2016)(Citation: ProofPoint Ursnif Aug 2016)

  16. [16]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  17. [17]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  18. [18]
    Gozi-ISFB

    (Citation: FireEye Ursnif Nov 2017)(Citation: ProofPoint Ursnif Aug 2016)

  19. [19]
    Gozi-ISFB

    (Citation: FireEye Ursnif Nov 2017)(Citation: ProofPoint Ursnif Aug 2016)

  20. [20]
    Gozi-ISFB

    (Citation: FireEye Ursnif Nov 2017)(Citation: ProofPoint Ursnif Aug 2016)

  21. [21]
    NJCCIC Ursnif Sept 2016

    NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.

    Open source URL
  22. [22]
    NJCCIC Ursnif Sept 2016

    NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.

    Open source URL
  23. [23]
    PE_URSNIF

    (Citation: TrendMicro Ursnif Mar 2015)

  24. [24]
    PE_URSNIF

    (Citation: TrendMicro Ursnif Mar 2015)

  25. [25]
    PE_URSNIF

    (Citation: TrendMicro Ursnif Mar 2015)

  26. [26]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  27. [27]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  28. [28]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  29. [29]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  30. [30]
    Ursnif

    (Citation: NJCCIC Ursnif Sept 2016)

  31. [31]
    Ursnif

    (Citation: NJCCIC Ursnif Sept 2016)

  32. [32]
    Ursnif

    (Citation: NJCCIC Ursnif Sept 2016)

  33. [33]
    mitre-attackS0386
    Open source URL
  34. [34]
    mitre-attackS0386
    Open source URL
  35. [35]
    mitre-attackS0386
    Open source URL
  36. [36]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  37. [37]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  38. [38]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  39. [39]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  40. [40]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  41. [41]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  42. [42]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  43. [43]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  44. [44]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  45. [45]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  46. [46]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  47. [47]
    NJCCIC Ursnif Sept 2016

    NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.

    Open source URL
  48. [48]
    NJCCIC Ursnif Sept 2016

    NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.

    Open source URL
  49. [49]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  50. [50]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  51. [51]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  52. [52]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  53. [53]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  54. [54]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  55. [55]
    TrendMicro Ursnif File Dec 2014

    Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.

    Open source URL
  56. [56]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  57. [57]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  58. [58]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  59. [59]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  60. [60]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  61. [61]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  62. [62]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  63. [63]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  64. [64]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  65. [65]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  66. [66]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  67. [67]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  68. [68]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  69. [69]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  70. [70]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  71. [71]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  72. [72]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  73. [73]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  74. [74]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  75. [75]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  76. [76]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  77. [77]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  78. [78]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  79. [79]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  80. [80]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  81. [81]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  82. [82]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  83. [83]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  84. [84]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  85. [85]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  86. [86]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  87. [87]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  88. [88]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  89. [89]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  90. [90]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  91. [91]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  92. [92]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  93. [93]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  94. [94]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  95. [95]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  96. [96]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  97. [97]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  98. [98]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  99. [99]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  100. [100]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  101. [101]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  102. [102]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  103. [103]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  104. [104]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  105. [105]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  106. [106]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  107. [107]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  108. [108]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  109. [109]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  110. [110]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  111. [111]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  112. [112]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  113. [113]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  114. [114]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  115. [115]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  116. [116]
    NJCCIC Ursnif Sept 2016

    NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.

    Open source URL
  117. [117]
    NJCCIC Ursnif Sept 2016

    NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.

    Open source URL
  118. [118]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  119. [119]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  120. [120]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  121. [121]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  122. [122]
    FireEye Ursnif Nov 2017

    Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

    Open source URL
  123. [123]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  124. [124]
    TrendMicro Ursnif File Dec 2014

    Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.

    Open source URL
  125. [125]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  126. [126]
    TrendMicro Ursnif File Dec 2014

    Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.

    Open source URL
  127. [127]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  128. [128]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.