Sinowal is a modular Windows banking trojan and bootkit-associated malware family used to steal financial and other sensitive data from infected systems. It became notable for combining master boot record infection and pre-OS stealth with browser-focused credential theft and fraud operations. Sinowal has been associated with the Torpig botnet and has historically been used in large-scale campaigns targeting online banking and e-commerce users worldwide.
Sinowal has been delivered through multiple vectors, including drive-by exploitation, spam-borne attachments, file-sharing distribution, and exploit kits such as Blackhole. In prominent campaigns, compromised websites redirected victims to exploit infrastructure that fingerprinted browsers and plug-ins, delivered tailored exploits, and installed a bootkit component that modified the MBR and forced a reboot. After restart, the malware executed before the operating system, hid its presence, and enrolled the host into botnet infrastructure that used rapidly changing command-and-control domains and domain-generation techniques.
The malware uses a staged, modular architecture. An installer deploys a loader, which retrieves a manager component and additional plug-ins from command-and-control servers. Modules are stored locally in encrypted form and can be updated or reloaded dynamically. Sinowal establishes persistence through both boot-level infection in some variants and Windows persistence mechanisms, and it injects into user processes to load components and interact with browsers.
Its primary mission is theft of banking and account data. Sinowal performs man-in-the-browser style interception in Internet Explorer, captures submitted form data including passwords, can execute server-supplied scripts, and supports fraudulent web-session manipulation such as opening phishing content and redirecting users. It also targeted Google Chrome by installing a malicious extension that monitored navigation, redirected traffic, forged referrers, intercepted session cookies, and stole submitted data. Additional modules harvested credentials and account information from email and FTP traffic, and some variants could capture screenshots and video from the victim system.
Sinowal also incorporated significant defense-evasion and anti-analysis features. It used encrypted communications and storage, process injection, stealthy bootkit techniques, and functionality intended to neutralize Trusteer Rapport on infected machines. Historical reporting also describes hidden in-memory spyware modules and resilient command-and-control operations using fast-flux-style infrastructure and DGA-based domain discovery.
The family is best characterized as a financially motivated banking malware platform focused on credential theft, session theft, and post-compromise fraud enablement against Windows users across global financial institutions and online services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
The Sinowal installer (MD5: 7efc5e7452d98843b9ae4a2678d057ea) may arrive on a victim’s computer via any of a number of different means, including drive-by download, spam attachment and file-sharing networks.
As a rule, this communication results in an additional module (a DLL) being downloaded to the victim machine.
Execute the command ‘regsvr32.exe /s {Path of Loader Module}’, which will cause the loader module to run in the regsvr32.exe process.
In order for a computer to become infected, the user had to not only open a page on the hacked site but also to click on the substitute link.
Make the registry value ‘HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’ point to the path of the loader module and add the path of the loader module to the registry value ‘HKLM\SOFTWARE\Microsoft\Windows NT\ CurrentVersion\Windows\LoadAppInit_DLLs’.
Inject a piece of code into the explorer.exe process to load the loader module.
Make the registry value ‘HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’ point to the path of the loader module and add the path of the loader module to the registry value ‘HKLM\SOFTWARE\Microsoft\Windows NT\ CurrentVersion\Windows\LoadAppInit_DLLs’.
Once the machine has rebooted, the bootkit hooks a range of system functions and starts to run fully in the system – hiding its own presence and functioning as a bot within a zombie network.
Depending on the ID assigned to the user, the server will generate an obfuscation key which will be used to encrypt the appropriate exploit.
The encryption routine performs a simple XOR operation on each double-word... The downloaded manager module will be decrypted with the key ‘HONNJCUPKFVBBYCC’.
The loader module is named ‘mini’ on 32-bit systems and ‘mi64’ on 64-bit systems... {Filename} is chosen from a given group...
Inject a piece of code into the explorer.exe process to load the loader module.
Execute the command ‘regsvr32.exe /s {Path of Loader Module}’, which will cause the loader module to run in the regsvr32.exe process.
A module named ‘gbsniffer.dll’ is employed to sniff network data and to harvest email addresses from POP3/SMTP traffic and the usernames/passwords of FTP client applications installed on the compromised machine.
...a newly created IDispatch object will be connected to the connection point for the DIID_HTMLInputTextElementEvents of each input text element... the value of this attribute is set to the content of the element – which is very likely the password entered by the compromised user.
The submitEvent function defined in the script will grab the form content when a form is submitted... This submitEvent method implemented in Crcl.dll will transfer stolen form data through a pipe to the manager module...
The script equips the extension with the capacity to redirect network traffic, forge the HTTP referrer, intercept session cookies, and monitor browser navigation.
A module named ‘gbsniffer.dll’ is employed to sniff network data and to harvest email addresses from POP3/SMTP traffic and the usernames/passwords of FTP client applications installed on the compromised machine.
...a newly created IDispatch object will be connected to the connection point for the DIID_HTMLInputTextElementEvents of each input text element... the value of this attribute is set to the content of the element – which is very likely the password entered by the compromised user.
The submitEvent function defined in the script will grab the form content when a form is submitted... This submitEvent method implemented in Crcl.dll will transfer stolen form data through a pipe to the manager module...
screen (dispId 0x05): take a screenshot in JPEG format and send it to the C&C server.
video (dispId 0x09): record an MPEG video of the user screen by using an open-source x264 library embedded in the Iecl module, and send the video to the C&C server.
The malicious program creates a specially crafted network packet using the ID of the infected computer and attempts to send it to the command and control server... As soon as one of the domains appears to be “correct” ... the bot will connect to it as a botnet client and starts encrypting communication with the command and control centre.
The manager module communicates directly with the C&C server, uploading stolen information, reporting the local status of the trojan and downloading configuration and plug-in modules... The HTTP session for downloading is shown in Figure 5.
The DLL acts as a loader module and will load other components, if any exist, and download a manager module which plays a central role in conducting banking fraud. The manager module downloads several plug-in modules from the C&C server...
If it’s not possible to connect to the command and control centre, the bot will use a dedicated algorithm to consecutively generate .com, .net and .biz domain names.
This method is similar to the Fast-Flux technology which is actively used by worms from the Zhelatin (Storm Worm) family.
Unlike the hard-coded C&C server URL used for downloading the manager module, the C&C server domains for downloading configuration data and plug-in modules are obtained through a DGA (Domain Generation Algorithm) which is based on the current date and time taken from Google.
As an advanced banking trojan, Sinowal is equipped with a weapon to defeat Trusteer Rapport... Suspend all threads belonging to the Trusteer Rapport module in the browser process... Recover APIs... Hook the NtCreateThread and NtCreateThreadEx APIs to abort threads created by Trusteer Rapport.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a functionally similar trojan for comparison with Gozi.
Referenced as another bootkit malware family that infects the MBR to execute before the operating system starts.
Sinowal is the classification given to the bootkit and associated spy DLL. It steals passwords, intercepts network traffic, targets banking sessions and website administration credentials, and can support man-in-the-middle and phishing-style interception.
Mentioned as a historical example of earlier bootkits during the peak bootkit era.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.