Ursnif Banking Trojan Uses Stealthy Memory Execution
ID: 1fdc0719-0f8d-54b8-8778-68b0a91dc011
STIX ID: report--1fdc0719-0f8d-54b8-8778-68b0a91dc011
Feed Name: Cyble Blog
Cyble Research and Intelligence Labs (CRIL) reports a targeted Ursnif banking-trojan campaign against U.S. business professionals using a ZIP-delivered .lnk masquerading as a PDF to invoke certutil and decode an HTA; the HTA drops a DLL and lure PDF, the DLL decrypts and executes shellcode and a second-stage DLL in memory, leading to the in-memory load of the Ursnif core which communicates with C2 (budalixt.top) to download modules and exfiltrate data; the report includes detailed technical analysis, TTP mapping to MITRE ATT&CK, YARA rule references, and multiple IOCs (hashes and URLs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
