logo

New Ursnif Campaign: From PowerShell to Mshta

ID: 1ce68678-42cc-5031-b193-71d6cdb21d99

STIX ID: report--1ce68678-42cc-5031-b193-71d6cdb21d99

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-10-10

Date Updated: 2026-05-01

...
...

**Ursnif multistage distribution (Mar 24, 2020):** Zscaler ThreatLabz analyzed a live campaign delivering the Ursnif banking trojan via a three-stage chain (malicious DOC macro -> obfuscated HTA executed by mshta -> index.dll downloaded and executed via regsvr32). The report documents the VBA/HTML/JavaScript payload behavior, decoded payload URL, newly registered domains, payload URLs, a download link and an MD5 hash for the payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.