SOC Alert! Uptick in Ursnif Distribution
ID: d74ed1f4-1aae-549a-8c74-2cb56127e3e4
STIX ID: report--d74ed1f4-1aae-549a-8c74-2cb56127e3e4
Feed Name: Binary Defense Blog
Threat Score
Ursnif is being distributed via reply-chain attacks using password-protected ZIPs with macro-enabled documents; the campaign uses a multi-stage loader that injects a malicious DLL into iexplore.exe, employs registry-based fileless persistence to re-execute, and communicates with listed C2 domains. Block the provided C2 domains, do not execute macros, and prioritize rapid remediation because infected hosts often receive Trickbot as a follow-on payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
