Ursnif Malware โ Italian Tax Agency lure
Between 8 and 21 March 2021 we identified a malicious email campaign distributing the Ursnif malware.
Ursnif malware is classified as a “๐ฉ๐๐๐๐๐๐ ๐ป๐๐๐๐๐”, primarily associated with user data compromise and frequently deployed as an initial vector for more complex infrastructure breaches and Ransomware attacks.
The email subject line mimics the Italian Revenue Agency (Agenzia delle Entrate), with a malicious Excel file “.xlsb” attached to the message.

The dropper
Upon opening the ๐๐ ๐ฐ๐ฒ๐น document and enabling Macros, a sequence of actions is initiated that includes downloading and executing the second stage of the malware (a “.dll” ๐๐๐๐).

Malware Behavior
The dropper downloads the dll ๐๐๐๐ from the domain satisonline[.]bar (62[.]173[.]147[.]107), retrieving the file “signup.jpg”. This activity is consistent with Cyber Threat Intelligence observations of Ursnif distribution infrastructure.

The ๐๐๐๐ is saved to a randomized directory path of the form: “C:\zVAJUlB\WPTqlPR\RjuoPEa.dll”
At this stage the endpoint is compromised, with initial connections established to “๐๐ผ๐บ๐บ๐ฎ๐ป๐ฑ ๐ฎ๐ป๐ฑ ๐๐ผ๐ป๐๐ฟ๐ผ๐น” servers for remote system access (T1071 – Application Layer Protocol, T1090 – Proxy).
Ursnif campaigns leveraging macro-enabled Office documents remain a persistent delivery mechanism for banking trojans. Organizations must enforce application whitelisting, disable macro execution by default, and maintain network-based detection signatures for known command-and-control infrastructure to mitigate this threat vector.