Cinobi is a Windows banking trojan associated with the Operation Overtrap cybercrime campaign and later activity attributed to Water Kappa. It has primarily targeted users in Japan, focusing on online banking customers and later expanding to include Japanese cryptocurrency trading services. The malware has been delivered through multiple infection chains, including a Japan-focused exploit-kit campaign using Bottle Exploit Kit against Internet Explorer and Adobe Flash vulnerabilities, as well as later malvertising and social-engineering lures that distributed archives abusing DLL sideloading with legitimate software components.
Cinobi is designed to steal financial account data and manipulate browser-based sessions. Documented capabilities include form-grabbing, web traffic modification, web injects, and DLL injection. It targets browser and network-relevant processes to intercept or alter traffic and user interactions. Later variants added Tor-based command-and-control communications, indicating an effort to improve resilience and concealment of backend infrastructure.
Observed Cinobi infections used a staged architecture, with multiple encrypted shellcode-based stages that download and execute additional components. The malware performs locale checks to ensure the victim environment is Japanese before proceeding. It has used encrypted configuration files and downloaded modules, UAC bypass via the CMSTPLUA COM interface, and persistence through installation of a malicious Winsock provider. In later campaigns, Cinobi was also delivered through malicious ZIP archives themed as popular consumer software or entertainment content for Japanese users, with execution initiated through DLL sideloading and subsequent staged payload decryption.
Cinobi is notable for its narrow geographic targeting, emphasis on Japanese financial institutions, and evolution from exploit-kit delivery to broader social-engineering and malvertising-based distribution. Its operational focus is credential theft and session manipulation in support of financial fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Bottle Exploit Kit is back, and has started exploiting CVE-2020-1380 and CVE-2021-26411 ... it exploits CVE-2020-1380 and CVE-2021-26411.
Another researcher later discovered the custom exploit kit, which was named the Bottle Exploit Kit (BottleEK). It exploits CVE-2018-15982, a Flash Player use after free vulnerability, as well as CVE-2018-8174, a VBScript remote code execution vulnerability.
Another researcher later discovered the custom exploit kit, which was named the Bottle Exploit Kit (BottleEK). It exploits CVE-2018-15982, a Flash Player use after free vulnerability, as well as CVE-2018-8174, a VBScript remote code execution vulnerability.
It also delivered the trojan using the Bottle exploit kit, which included newer Internet Explorer exploits CVE-2020-1380 and CVE-2021-26411 and was used for malvertising attacks. | In a previous blog entry, we reported on a campaign, which we labeled “Operation Overtrap,” that targeted Japan with a new banking trojan called Cinobi... the configuration had been updated to include several Japanese cryptocurrency exchange websites as part of the target list.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In a previous blog entry, we reported on a campaign, which we labeled “Operation Overtrap,” that targeted Japan with a new banking trojan called Cinobi... the configuration had been updated to include several Japanese cryptocurrency exchange websites as part of the target list.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
I thought Drive-by Download attack was dead four years ago... However, even if in 2021, it will not disappear... Drive-by Download attacks are still being observed.
PurpleFox Exploit Kit has started exploiting CVE-2021-26411 RIG Exploit Kit has started exploiting CVE-2021-26411 Bottle Exploit Kit is back, and has started exploiting CVE-2020-1380 and CVE-2021-26411
the campaign uses three different attack vectors to steal its victims’ banking credentials: • By sending spam emails with a phishing link to a page disguised as a banking website • By sending spam emails asking victims to execute a disguised malware’s executable downloaded from a linked phishing page.
The shellcode embedded into format.cfg copies config.dll and cfg.config to the temporary directory %TEMP%, renames these files to a.dll and 1.txt, and executes the export function named “a” of the a.dll library via the following command: rundll32.exe "%TEMP%\a.dll",a %TEMP%\1.txt
In practice, Cinobi should be injected into all processes that make network connections using Windows sockets.
Each of Cinobi’s four stages contains an encrypted position-independent shellcode that makes analysis slightly more complicated.
After extracting the Tor archive into the “\AppData\LocalLow\” directory, Cinobi will rename tor.exe to taskhost.exe and execute it.
In practice, Cinobi should be injected into all processes that make network connections using Windows sockets.
the first one has a DLL library injection payload that compromises victims’ web browsers to perform form-grabbing.
Check the version of Internet Explorer, Adobe Flash Player, and the architecture of the infected machine. It then sends the gathered information with an Ajax request to the exploit kit hosting server
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage banking trojan used in campaigns targeting Japan. It is delivered via malvertising and sideloading, performs staged loading and decryption, uses C2 infrastructure to retrieve additional stages and configuration, and steals credentials through form-grabbing from Japanese financial institutions including cryptocurrency exchanges.
Unique malware delivered by the Bottle exploit kit.
A banking trojan used in Operation Overtrap to steal credentials from Japanese online banking users. It performs form-grabbing, can modify web traffic and webpages via webinjects, uses a multi-stage infection chain, and in its second version communicates with C2 over Tor. It also installs as a Winsock provider, injects into browsers and networked processes, disables security/update services, and targets Japan-based financial institutions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.