Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0386
MITRE ATT&CK Malware

Ursnif (S0386)

Gozi-ISFBPE_URSNIFDreambot
ShareXLinkedInRedditHN

[Ursnif](https://attack.mitre.org/software/S0386) is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001)s, and malicious links.(Citation: NJCCIC Ursnif Sept 2016)(Citation: ProofPoint Ursnif Aug 2016) [Ursnif](https://attack.mitre.org/software/S0386) is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.(Citation: TrendMicro Ursnif Mar 2015)

Platforms: Windows

▪Techniques implemented (35)

T1007System Service DiscoveryT1547.001Registry Run Keys / Startup FolderT1105Ingress Tool TransferT1027.013Encrypted/Encoded FileT1090.003Multi-hop ProxyT1074.001Local Data StagingT1106Native APIT1497.003Time Based ChecksT1559.001Component Object ModelT1056.004Credential API HookingT1057Process DiscoveryT1041Exfiltration Over C2 ChannelT1132Data EncodingT1055.005Thread Local StorageT1140Deobfuscate/Decode Files or InformationT1036.005Match Legitimate Resource Name or LocationT1005Data from Local SystemT1027.010Command ObfuscationT1113Screen CaptureT1543.003Windows ServiceT1059.001PowerShellT1071.001Web ProtocolsT1070.004File DeletionT1012Query RegistryT1112Modify RegistryT1568.002Domain Generation AlgorithmsT1059.005Visual BasicT1082System Information DiscoveryT1090ProxyT1047Windows Management InstrumentationT1055.012Process HollowingT1185Browser Session HijackingT1080Taint Shared ContentT1091Replication Through Removable MediaT1564.003Hidden Window

▪Used by groups (1)

G0127TA551
S0386on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.