The Ursnif malware has become the latest malware to transform/revamp from a banking trojan into a general backdoor capable of delivering next-stage payloads.
See also: USA: Two men sentenced to two years in prison for cryptocurrency theft

See also: A new version of Android spyware Furball has been detected
Banking malware is some of the oldest malware in circulation, but it is still relevant today. A backdoor form of this malware has been classified as “significantly dangerous” and it is possible that attackers will use it for ransomware attacks in the future.
The new version of the Ursnif malware – also known as Gozi – is specifically designed for data theft and ransomware attacks, according to researchers at security firm Mandiant.
The first Ursnif malware, specifically designed to steal banking information, appeared in 2006. Since then, it has caused tens of millions of dollars in losses worldwide. The Federal Bureau of Investigation (FBI) ranks it as “one of the most economically devastating computer viruses in history.” To make matters worse, the original source code for this malware was leaked online .
Ursnif's original goal was to steal banking information, but a new variant - called LDR4 - has changed that, drawing inspiration from Trickbot and Emotet.
Attackers using the malware could not only steal data but also install ransomware. The latter would cause much more damage than stealing banking details and provide more profit to the hackers.
According to Mandiant, LDR4 can be a serious threat, as it is capable of distributing ransomware. This new variant was first observed in June and uses the same distribution method used by previous Ursnif campaigns and many other malware attacks, phishing emails.

Many of these phishing emails appear to come from a recruiter offering a new job opportunity. The message may state that, due to GDPR (General Data Protection Regulation), they cannot provide any more information in the email and urges the victim to download a document for more details. Other phishing emails claim that the message highlights an invoice that needs immediate attention.
Even if a phishing email seems trustworthy, following the instructions in the message will result in downloading the Ursnif malware to your computer, giving attackers access to your machine.
See also: New PowerShell backdoor disguises itself as Windows Update
According to Mandiant researchers, this is a significant shift from the malware's original purpose of banking fraud, but it is consistent with the broader threat landscape.
Information source: zdnet.com
