logo

Phishing Campaigns featuring Ursnif Trojan on the Rise

ID: 39bdb0dd-d457-52d9-93ac-e5c2537accda

STIX ID: report--39bdb0dd-d457-52d9-93ac-e5c2537accda

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2022-06-08

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs describes a mass-phishing campaign using malicious Microsoft Word documents with obfuscated VBA macros that extract reversed strings from custom document properties, load and execute shellcode in memory, set an environment variable containing a URL, download an Ursnif DLL to a temporary file, and execute it via rundll32; the report includes static macro analysis, IOCs (file hashes and download URL), detection names, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.