Ursnif has collected files from victim machines, including certificates and cookies.4
tool
Ursnif S0386
- Type
- malware
- Platform
- Windows
- Created
- 4 June 2019
- Last modified
- 12 September 2024
Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0386
Ursnif has used Reg to query the Registry for installed programs.67
Ursnif droppers execute base64 encoded PowerShell commands.8
Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk.9 Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands.10
Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names.11
Standing S0386
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
96th percentile · 96% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
100th percentile · None of the 825 ATT&CK software entries has more tactics spanned — the highest in the population.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
29th percentile · 71% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S0386
1130 distinct rules cover the 35 techniques recorded for this tool. The 1232 technique-to-rule mappings resolve to 1130 distinct rules, because one rule can cover several techniques. 779 Sigma · 351 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org