logo

Ursnif Banking Trojan Uses Stealthy Memory Execution

ID: 1fdc0719-0f8d-54b8-8778-68b0a91dc011

STIX ID: report--1fdc0719-0f8d-54b8-8778-68b0a91dc011

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-04-22

Date Updated: 2026-07-16

...
...

Cyble Research and Intelligence Labs (CRIL) reports a targeted Ursnif banking-trojan campaign against U.S. business professionals using a ZIP-delivered .lnk masquerading as a PDF to invoke certutil and decode an HTA; the HTA drops a DLL and lure PDF, the DLL decrypts and executes shellcode and a second-stage DLL in memory, leading to the in-memory load of the Ursnif core which communicates with C2 (budalixt.top) to download modules and exfiltrate data; the report includes detailed technical analysis, TTP mapping to MITRE ATT&CK, YARA rule references, and multiple IOCs (hashes and URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.