Ursnif Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
October 31, 2025
Last Seen
July 1, 2026

Ursnif is a long-standing banking Trojan family known for credential theft and data exfiltration, often deployed via loaders and downloaders.

Overview

Ursnif is a long-standing banking Trojan family known for credential theft and data exfiltration, often deployed via loaders and downloaders. The recent reports tie Ursnif to attacks that abuse a Windows LNK shortcut vulnerability exploited as a zero-day, highlighting the threat's ongoing adaptation to Windows flaws and its relevance in current threat activity.

Related Threat Clusters

Recent Intelligence Reports

  • 012 — attack.mitre.org · July 1, 2026
  • Ransomware gang uses ISPsystem VMs for stealthy payload delivery — Bleepingcomputer · February 5, 2026
  • Proofpoint details TA584's fast-evolving 2025 attacks — Securitybrief.Au · January 30, 2026
  • Proofpoint details TA584's fast-evolving 2025 attacks — Itbrief · January 30, 2026
  • Initial access hackers switch to Tsundere Bot for ransomware attacks — Bleepingcomputer · January 28, 2026
  • Can’t stop, won’t stop: TA584 innovates initial access — Proofpoint · January 28, 2026
  • Microsoft "mitigates" Windows LNK flaw exploited as zero — Bleepingcomputer · December 3, 2025
  • Windows zero — Bleepingcomputer · October 31, 2025

CVSS v3.1 Breakdown