Netskope Threat Labs

Ursnif

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Ursnif (a.k.a. Gozi) is a banking trojan and backdoor whose source code leaked in the mid 2000s, which allowed cyberattackers to create and distribute many variants. It steals credentials through form grabbing and web injects, and its modular builds served as loaders for ransomware and other payloads across years of campaigns. The family's leaked code base made it a foundation for numerous rebrands, and its behavior still surfaces in modern commodity malware.

First seen
January 2022
Last seen
October 2026
Dreambot

35 techniques across 9 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1007System Service Discovery
  • T1012Query Registry
  • T1057Process Discovery
  • T1082System Information Discovery

TA0008 Lateral Movement

  • T1080Taint Shared Content
  • T1091Replication Through Removable Media

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
ByteCode-MSIL.Trojan.Ursnif
DeepScan:Generic.Ursnif.1.2CF23DC0
DeepScan:Generic.Ursnif.1.489F6A39
DeepScan:Generic.Ursnif.1.C869A380
DeepScan:Generic.Ursnif.3.1.016935FD
DeepScan:Generic.Ursnif.3.1.2DF55147
DeepScan:Generic.Ursnif.3.1.C637C256
DeepScan:Generic.Ursnif.3.1.D4EE9B95
Document-Excel.Trojan.Ursnif
Document-HTML.Trojan.Ursnif