logo

SOC Alert! Uptick in Ursnif Distribution

ID: d74ed1f4-1aae-549a-8c74-2cb56127e3e4

STIX ID: report--d74ed1f4-1aae-549a-8c74-2cb56127e3e4

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Ursnif is being distributed via reply-chain attacks using password-protected ZIPs with macro-enabled documents; the campaign uses a multi-stage loader that injects a malicious DLL into iexplore.exe, employs registry-based fileless persistence to re-execute, and communicates with listed C2 domains. Block the provided C2 domains, do not execute macros, and prioritize rapid remediation because infected hosts often receive Trickbot as a follow-on payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.