BackSwap is a Windows banking trojan first observed in 2018 and widely assessed as a variant of Tinba. It primarily targeted online banking users in Poland and later shifted heavily toward Spanish banks, with some activity also affecting cryptocurrency wallet users. The malware is notable for implementing much of its functionality as position-independent assembly code embedded inside trojanized legitimate applications, allowing it to execute before the host program’s normal entry point and complicating static analysis.
BackSwap’s core purpose is banking fraud and credential theft. Rather than relying solely on traditional browser memory injection, it monitors browser and UI activity, identifies visits to targeted financial sites, decrypts locally stored web-inject code from its resources, and injects malicious JavaScript into active browser sessions through simulated user interaction. Observed techniques include abusing browser developer tools and the address bar to paste or execute JavaScript. The injected code manipulates banking-site DOM elements by cloning legitimate transfer form fields, hiding the originals, presenting visually convincing fake fields to the victim, and silently submitting attacker-controlled beneficiary details in the real fields. This enables recipient-account substitution during otherwise legitimate transactions.
The malware has also been observed stealing credentials and transaction data via browser-focused mechanisms such as clipboard interaction, window-title manipulation, and logging of captured data for later transmission. Some variants monitor accessibility or UI events to harvest information, and some alter clipboard contents when bank-account or cryptocurrency-wallet patterns are detected. BackSwap stores its fraud logic locally in encrypted resource data instead of depending on remotely fetched webinjects, a design choice that reduces operational exposure and can help it remain effective even when command-and-control connectivity is limited.
Technically, BackSwap uses custom runtime API resolution, Process Environment Block traversal, hashed import lookup, and obfuscated string-handling techniques. It has evolved repeatedly, changing resource layouts, obfuscation methods, and web-inject packaging, including versions that concealed encrypted payloads inside image data. It commonly masquerades as benign software and has been associated with compromised legitimate websites for backend communications. BackSwap is regarded as an innovative banker because it performs fraud locally in the browser session while emphasizing stealth, evasion, and minimal reliance on overt in-memory browser injection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
disable protection from pasting code inside JavaScript console, it’s achieved with the following command: /V:ON /C dir /S/B/A-D “%APPDATA%\Mozilla\prefs.js” > “%TEMP%\edit” && SETLOCAL EnableDelayedExpansion && set /p v=<“%TEMP%\edit” && echo ^user_pref(“devtools.selfxss.count”, 100); >> “!v!”
A trojan is any type of malicious program disguised as a legitimate one.
they hijacked a piece of code that initializes internal data structures by invoking a set of callbacks from a predefined function pointer table. This table (used by the __initterm() function from CRT) is added with an additional pointer, that will in turn cause the C runtime to invoke the malware’s code before executing the original program.
disable protection from pasting code inside JavaScript console... echo ^user_pref(“devtools.selfxss.count”, 100); >> “!v!”
BackSwap would create several threads and setup event hooks for a range of events using the SetWinEventHook function. Although there are some changes in this behavior between different versions of the malware, the essential logic is the same.
Whenever the victim entered one of the targeted banking websites and wanted to perform a transaction, the web-inject code would replace the target IBAN with the aforementioned one, thus transferring the money to the attackers instead of the real intended recipient.
We observed some modifications in the PIC payload, especially more encryption layers and tons of junk-code that is meant to make the analysis more complicated as well as making the malware harder to detect.
Backswap loads functions from libraries by comparing simple hash of the name of the function with table of hashes stored inside the binary.
In this technique, the PIC described before is encrypted, and embedded inside a BMP image... The decryption routine is quite simple and can be easily analyzed.
BackSwap hides as a legitimate running application such as 7zip or OllyDbg, which are applications not commonly run by typical users.
it uses a common technique, used mostly in injected code, whereby the PEB structure (Process Environment Block) is processed in order to find the list of loaded modules, from which the address of kernel32.dll can be retrieved.
it determines if a Windows event object which has the name pattern <USERNAME>-<COMPUTERNAME> already exists. If so, the malware will terminate the execution, as it infers another copy is running in the system.
Send CTRL+SHIFT+J keyboard combination to the browser process for Internet Explorer/Google Chrome, and CTRL+SHIFT+K for Firefox... SendInput is used... malware sends CTRL+V , then ENTER
Hide browser window... Those are extended with attribute WS_EX_LAYERED... This results in window being transparent, not visible to the user
they hijacked a piece of code that initializes internal data structures by invoking a set of callbacks from a predefined function pointer table. This table (used by the __initterm() function from CRT) is added with an additional pointer, that will in turn cause the C runtime to invoke the malware’s code before executing the original program.
disable protection from pasting code inside JavaScript console... echo ^user_pref(“devtools.selfxss.count”, 100); >> “!v!”
Whenever the victim entered one of the targeted banking websites and wanted to perform a transaction, the web-inject code would replace the target IBAN with the aforementioned one, thus transferring the money to the attackers instead of the real intended recipient.
the hooked events are intended to intercept activity that occurs with relation to window applications across the computer. | Instead of injecting code straight to the browser’s memory, the malware mimics a user interaction with the browser’s window by sending keystrokes to it. Namely, It opens the browser’s Developer’s Tools or sets the focus to the URL bar and pastes the malicious javascript by faking a press on Ctrl+V.
In newer versions of BackSwap, if a URL was found, the malware will in turn decrypt a resource from its .rsrc section which turns out to be its web-injects, a piece of javascript code that is injected to the internet browser in order to manipulate objects in pages visited by the user.
With the help of SetWinEventHook following events are hooked... Configured callback function for those events saves window title text to the log file | Backswap carries out multiple harmful activities. Big ones are: injecting Webinjects and stealing credentials... It swaps the account number of the money transfer recipient using injected JavaScript code.
Whenever the victim entered one of the targeted banking websites and wanted to perform a transaction, the web-inject code would replace the target IBAN with the aforementioned one, thus transferring the money to the attackers instead of the real intended recipient.
Configured callback function for those events saves window title text to the log file located in %TEMP%/<nazwa>.log
the hooked events are intended to intercept activity that occurs with relation to window applications across the computer. | Instead of injecting code straight to the browser’s memory, the malware mimics a user interaction with the browser’s window by sending keystrokes to it. Namely, It opens the browser’s Developer’s Tools or sets the focus to the URL bar and pastes the malicious javascript by faking a press on Ctrl+V.
In newer versions of BackSwap, if a URL was found, the malware will in turn decrypt a resource from its .rsrc section which turns out to be its web-injects, a piece of javascript code that is injected to the internet browser in order to manipulate objects in pages visited by the user.
With the help of SetWinEventHook following events are hooked... Configured callback function for those events saves window title text to the log file | Backswap carries out multiple harmful activities. Big ones are: injecting Webinjects and stealing credentials... It swaps the account number of the money transfer recipient using injected JavaScript code.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware targeting primarily Polish banks and sometimes cryptocurrency wallets. It injects malicious JavaScript into browser sessions, swaps recipient account numbers during transfers, steals credentials, logs captured data, and communicates with C2 infrastructure. Some variants also hijack clipboard contents when bank or cryptocurrency account numbers are detected.
A banking trojan referenced for technique overlap with Dtrack droppers, particularly hiding malicious code inside replicas of legitimate programs and patching the initialization phase of executables.
Tinba variant written entirely in assembly as position-independent code, initially targeting Polish banks before shifting geographically to Spanish banks.
BackSwap is mentioned as a malware family whose scripts closely resemble some DanaBot scripts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.