Researchers detailed BackSwap, a banking trojan linked to the TinBa malware family, that targeted online banking users by hiding inside trojanized legitimate Windows applications such as 7-Zip, FileZilla, and Notepad++. First observed in 2018, the malware focused on Polish banks and later shifted heavily toward Spanish financial institutions, while also occasionally targeting cryptocurrency wallet users. Its operators used compromised legitimate websites as command-and-control infrastructure and repeatedly changed encryption keys, payload storage, and exfiltration methods to evade detection.
BackSwap stood out for avoiding classic browser memory injection and instead manipulating browser sessions through Windows UI monitoring and simulated user actions. It delivered malicious JavaScript into active banking sessions, stole credentials, logged browser window titles and URLs, hijacked clipboard data, and replaced recipient account numbers to redirect transactions to attacker-controlled IBANs. Analysts said the malware stored XOR-obfuscated or encrypted web-injects in the .rsrc section, sometimes concealed shellcode in BMP images, and used position-independent code plus custom Windows API resolution to reduce its forensic footprint and bypass antivirus heuristics.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
In August 2018, BackSwap began storing multiple web-injects in a single resource separated by markers such as [start:] and [fartu:]. Later samples added further separators including [mumuo:], [pghtyq], [tempo:], [code:], [joke:], and [asap:].
In June 2018, F5 Labs documented that BackSwap performed banking fraud locally in the browser by injecting JavaScript from its PE resources, cloning visible beneficiary fields, hiding the originals, and submitting attacker-controlled account details instead. The report also noted newer samples had renamed resource sections and began obfuscating the fraudster IBAN with a switch-based decoding routine.
In June 2018, BackSwap introduced a technique that encrypted its position-independent payload and embedded it inside BMP images. The malware used BMP headers as valid x86 instruction bytes to help disguise the shellcode.
In May 2018, BackSwap samples changed their web-inject resource encryption keys repeatedly, including multiple distinct single-byte XOR keys. During the same month, the malware used HTTP requests to yadro.ru to track the number of infected machines.
In April 2018, some BackSwap samples were configured to target up to six banks within a single binary. This marked an expansion beyond narrower earlier targeting.
BackSwap was first observed around March 2018 as a banking trojan targeting Polish online banking users. Early samples mainly targeted Polish banking sites including ipko.pl, 24.pl, and mbank.pl.
By late 2018, analysis showed BackSwap had shifted from initially targeting banks in Poland to focusing almost entirely on banks in Spain. The report also documented repeated changes in web-inject delivery and exfiltration methods across 2018.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourceresearch.checkpoint.com
Open sourcef5.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.