Nuclear Bot, also known as NukeBot, is a Windows banking trojan sold in underground markets and later publicly released as source code by its self-identified author, a French developer linked in reporting to Augustin Inzirillo. It was marketed as a ZeuS-like banking malware platform focused on credential theft and browser manipulation against financial websites.
The malware is structured around multiple components, including a dropper, a bot module, and a webinject-enabled man-in-the-browser engine. The dropper uses anti-analysis and anti-debugging measures, obfuscated library loading, API hashing, and environment checks intended to evade sandboxes, virtual machines, and reverse-engineering tools. It establishes persistence on Windows and injects a bot DLL into a system process. The bot communicates with a command-and-control server over HTTP, registers host information, polls for tasking, and supports functions including download-and-execute, SOCKS proxying, remote access via VNC, and self-update.
Its core banking capability is implemented through browser-focused injection. Nuclear Bot injects into user and browser processes, hooks browser networking functions, monitors web traffic, retrieves webinject rules from its command infrastructure, and modifies banking sessions in the victim browser. This enables credential theft and arbitrary content injection into targeted banking websites, consistent with man-in-the-browser tradecraft used to capture online banking credentials and manipulate web sessions.
Public advertising around Nuclear Bot claimed additional capabilities such as bypassing IBM Trusteer Rapport, but IBM researchers assessed those claims as unfounded and reported that Rapport protections remained effective. Contemporary technical analysis suggested some observed samples reflected a development or test-stage botnet rather than a mature, broadly deployed operation, citing unfinished webinject content and debugging artifacts.
Nuclear Bot is associated with later derivative activity because its source code became publicly available, increasing the likelihood of reuse by other criminals. Reporting also links its author to subsequent cybercrime activity and to custom variants such as TinyNuke used in campaigns against banking customers in Europe. Nuclear Bot is best understood as a banking trojan family for Windows that combines persistence, process injection, command-and-control tasking, and browser-based credential theft against financial targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The author of a banking Trojan called Nuclear Bot — a teenager living in France — recently released the source code for his creation just months after the malware began showing up for sale in cybercrime forums.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The library names are obfuscated with XOR and a hardcoded key... The reply from the C2 server will be a hex string that will be used as an XOR key to obfuscate further C2 communications.
After things are setup, an svchost (-k netsvcs) process is started and a DLL is injected into it... once it receives a PID it will inject the “engine” component into that process.
It will then perform three types of anti-analysis: Detecting common analysis software such as IDA Pro and Sysinternals tools Detecting common sandbox and virtual machines Detecting debugging via a timing check If it detects it is being run in an analysis environment it will delete itself.
Before transitioning to the next component some system information is written to a “<botid>.txt” text file... The system information is pipe delimited and consists of: info Windows version Computer name Username isWow64 status is Admin status
It will then perform three types of anti-analysis: Detecting common analysis software such as IDA Pro and Sysinternals tools Detecting common sandbox and virtual machines Detecting debugging via a timing check If it detects it is being run in an analysis environment it will delete itself.
It also phones home to a command and control (C2) server... After this initial setup an empty HTTP POST request is sent to the C2 server... Commands are polled with a “ping” command.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware with a dropper, bot, and webinject/Man-in-the-Browser components. It establishes persistence, injects into svchost and browsers, communicates with a C2 server, supports download-and-execute, VNC, SOCKS4 proxy, self-update, and steals credentials by injecting malicious content into targeted banking and other websites.
Mentioned only as a comparison point for how Matrix Banker might evolve.
A banking trojan designed to steal banking credentials from victims. The article ties it to the accused sextortion scam mastermind and notes its source code was released publicly, enabling reuse by other criminals.
A banking trojan authored by one of the charged individuals; the content also notes its source code was released after it appeared for sale on cybercrime forums.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.