Tinba, also known as Tiny Banker and Zusy, is a compact Windows banking trojan and information-stealing malware family first publicly identified in 2012. It is notable for its unusually small footprint and for focusing on browser-centric theft of online banking credentials, browsing data, and other sensitive information. Tinba is associated with man-in-the-browser activity, browser hooking, webinjects, and network traffic monitoring to capture credentials and manipulate banking sessions in real time. Its webinject capability has been used to alter pages presented to victims and to solicit additional authentication data, including information that can help bypass or abuse two-factor authentication workflows.
On infected systems, Tinba injects code into system and browser processes to conceal activity and intercept user data. Reported behavior includes injection into common Windows processes and hooks targeting major browsers such as Internet Explorer, Chrome, Firefox, and Opera. Tinba has used anti-analysis measures including custom packing and debugger checks, and it has established persistence by copying itself into user-profile application data locations and configuring automatic execution at startup. Some variants generate mutex values derived from host-specific information.
Tinba communicates with command-and-control infrastructure to retrieve configuration data, target lists, and webinject content, and it has been observed using both hardcoded infrastructure and domain-generation-algorithm-based fast-flux communications. Stolen information has included credentials from banking sites as well as data from webmail and social-media services. Tinba has also been linked to shared webinject techniques and configuration patterns seen across other banking malware ecosystems, reflecting code reuse and overlap common in financially motivated malware development.
Distribution has included spam email attachments, drive-by delivery, and exploit-kit activity, including observed use via Angler. Tinba has appeared in geographically targeted banking campaigns and has remained part of the broader banking-trojan landscape alongside families such as Zeus, Gozi, Dridex, and KINS. Its lineage has also influenced later malware, including BackSwap, which has been assessed as a Tinba variant or descendant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Caphaw avoids local detection by injecting itself into legitimate processes such as explorer.exe or iexplore.exe... Further evidence of this being Caphaw exists in the banking information that it is listening for once it is injected into key Windows Processes.
The general procedure is to get access to the target process using OpenProcess , allocating memory in the process using VirtualAlloc , writing malicious code to the allocated memory with WriteProcessMemory and finally having this code execute using CreateRemoteThread .
Backswap loads functions from libraries by comparing simple hash of the name of the function with table of hashes stored inside the binary.
injects itself into the newly created process “winver.exe” (Version Reporter Applet) dropped into the windows system folder.
Caphaw avoids local detection by injecting itself into legitimate processes such as explorer.exe or iexplore.exe... Further evidence of this being Caphaw exists in the banking information that it is listening for once it is injected into key Windows Processes.
The general procedure is to get access to the target process using OpenProcess , allocating memory in the process using VirtualAlloc , writing malicious code to the allocated memory with WriteProcessMemory and finally having this code execute using CreateRemoteThread .
Backswap carries out multiple harmful activities. Big ones are: injecting Webinjects and stealing credentials. | TinBa in 2015... was using various techniques: ... Form grabbing to steal users credentials
Formbook ... can retrieve authorization and login credentials from a web data form before the information reaches a secure server, bypassing HTTPS encryption. ... Formgrabbers intercept HTTP(S) data and use inline hooking ... to capture a user's information before the user submits it
Backswap carries out multiple harmful activities. Big ones are: injecting Webinjects and stealing credentials... It swaps the account number of the money transfer recipient using injected JavaScript code.
The main purpose of the malware is to steal information that could be browsing data, login credentials, or even banking information.
A system infected with Avalanche-associated malware may be subject to malicious activity including the theft of user credentials and other sensitive data, such as banking and credit card information.
Backswap carries out multiple harmful activities. Big ones are: injecting Webinjects and stealing credentials. | TinBa in 2015... was using various techniques: ... Form grabbing to steal users credentials
Formbook ... can retrieve authorization and login credentials from a web data form before the information reaches a secure server, bypassing HTTPS encryption. ... Formgrabbers intercept HTTP(S) data and use inline hooking ... to capture a user's information before the user submits it
Backswap carries out multiple harmful activities. Big ones are: injecting Webinjects and stealing credentials... It swaps the account number of the money transfer recipient using injected JavaScript code.
The collected information form webmail, social media and the banking sites are stored in "log.dat" file.
The POST request to C&C server contains encrypted system information like system volume & version information.
Background thread periodically sends log file contents to the C&C server.
The main components are copied into the [%userprofile%]/Application Data/Default/ bin.exe and the encrypted configuration file “cfg.dat” accompanied by the webinject file named “web.dat”.
Another thread is also created in Explorer process which is responsible for generating DGA (Domain Generation Algorithm) domains
These DGA domains are fast flux domains where single domain is frequently switched to different IPs by registering it as part of the DNS A record list for a single domain.
242 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older banking trojan family described as the basis or variant lineage for Backswap. The content notes TinBa used techniques such as DGA for C2 communication, form grabbing to steal credentials, and process injection.
Information-stealing banking trojan that injects into system processes and browsers, steals browsing, login, webmail, social media, and banking data, persists via %APPDATA% copy and autorun registry entry, and uses DGA-based C2 communication.
PC banking trojan listed among malware actively used to attack companies.
Tinba is a banking trojan known for stealing online banking credentials and financial information from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.