Ursnif Trojan – Stealthy Memory Execution

T1566.001 – Attackers send emails containing a malicious LNK file disguised as a PDF document, likely targeting business professionals in the United States.

T1140 – The LNK file uses certutil.exe to decode a Base64-encoded payload.

T1562.004 – The malware uses PowerShell commands to disable Windows Defender.

T1059.003 – The decoded payload is executed using cmd.exe, leading to the execution of the Ursnif banking Trojan.

T1071.001 – The malware establishes communication with a command-and-control (C2) server using web protocols, likely HTTP or HTTPS.

T1041 – The malware exfiltrates stolen sensitive information, such as banking credentials and personal data, to the C2 server.