KINS is a Windows banking Trojan and Zeus-derived crimeware family that emerged after the 2011 leak of the ZeuS source code. It is also referred to as ZeusVM in some reporting and has been described as a successor or competitor within the broader Zeus-family ecosystem alongside variants such as Citadel and Ice-IX. KINS has been active since at least 2011 and has appeared in financially motivated campaigns targeting online banking users in multiple countries, including parts of Europe and Japan.
KINS is associated with credential theft and online banking fraud. Reported behavior includes encrypted collection of host and system information, command-and-control communications from injected code, and code injection into Windows processes such as explorer.exe. It has also been documented modifying Windows security settings to weaken host defenses, including changes affecting firewall, antimalware, and notification settings, indicating deliberate defense evasion. KINS has been linked to the ATSEngine ecosystem used to automate theft from financial accounts, and it is part of the long-running lineage of Zeus-based malware that relies on web-injection-driven banking fraud.
Observed delivery methods include malvertising and spam-driven distribution chains. In one documented campaign, users visiting European transit-related websites were redirected through advertising infrastructure to a payload masquerading as a PDF document, after which the malware established itself on the system and communicated with its operators. Separate telemetry also places KINS among payloads delivered through large spam-borne banking Trojan operations that used downloader malware and compromised web infrastructure. KINS has additionally been cited in research on malware using steganographic techniques, reflecting overlap with broader Zeus-family tradecraft.
KINS targets Windows systems and is best characterized as a banking Trojan focused on financial theft, host compromise, and evasion rather than destructive activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The bot encrypts the system information in the following format and sends it via the above POST request to the C&C server
The malware masquerades as a PDF document to lure an unsuspecting user into opening the file.
Microsoft security center - disable update notifications, disable antimalware scan... Windows firewall settings - Allow exceptions, disable notifications, disable the firewall... Windows Defender & AntiMalware settings - Exclude malware processes, injected system processes and certain file types from scanning
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Семейство вредоносного ПО, упомянутое как использующее стеганографию для сокрытия данных или коммуникаций.
A Zeus-derived banking trojan/crimekit delivered via malvertising. It masquerades as a PDF, copies itself into Application Data, deletes the original, injects into explorer.exe, modifies registry settings to weaken Security Center, Firewall, Windows Defender, and Microsoft Antimalware protections, opens TCP port 36139 for incoming connections, and performs encrypted C2 communications to exfiltrate system information.
A banking trojan mentioned as an example of malware that used simpler, non-digital steganographic techniques by appending data to image files.
PC banking trojan listed among malware actively used to attack companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.