TinyNuke is a malware family referenced in the provided content as a known point of comparison for web-injection behavior and as a payload observed in criminal delivery ecosystems. In the 2018 Flare-On Challenge 4 write-up, a dropped DLL named browserassist.dll was persisted via the AppInit_DLLs registry value at HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs, targeted firefox.exe, checked for Firefox versions lower than 55, downloaded Base64-encoded encrypted data from hxxp://pastebin.com/raw/hvaru8NU, decrypted it with RC4 using the key md5("FL@R3ON.EXE"), and used the resulting JSON to replace matching webpage code with attacker-supplied content; the write-up explicitly states this web-injection technique is similar to TinyNuke malware. Separately, TinyNuke is listed among malware families observed in BraZZZerS fast-flux/proxy infrastructure logs, indicating it appeared in that criminal hosting ecosystem, and it is also listed among payloads delivered in observed malware chains, including StealC-linked delivery activity. The provided content does not supply higher-confidence details on TinyNuke’s full feature set, infection vector, specific threat actor attribution, or dedicated indicators of compromise beyond these references.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
If the operator adds loader URLs, the StealC clients (bots) that connect to the C2 server will be delivered one or more of these loader URLs. At this point, the StealC malware client will attempt to download and execute one of the payloads from the URLs provided by the server.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family observed as a payload in StealC-related delivery chains.
TinyNuke was observed as a payload in StealC-related operations.
Banking trojan observed in BraZZZers logs.
TinyNuke is referenced as a malware example for web-injection behavior; the analyzed DLL performs browser injection into Firefox and modifies web content based on JSON rules, similar to TinyNuke-style web injects.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.