Kaspersky researchers reported that the public release of the NukeBot banking trojan source code led to a wave of derivative malware samples, but only a small fraction were fully operational. Analysis of multiple compiled samples found that many were unfinished or misconfigured, often pointing to localhost or private-network command-and-control addresses, while a smaller set connected to live infrastructure and could be used in real attacks.
By emulating bot-to-C2 communications, the researchers recovered web inject configurations showing that active NukeBot deployments primarily targeted banks in France and the United States. The investigation also uncovered modified variants that dropped the trojan’s web-injection capability and instead focused on credential theft, downloading password-recovery tools from malicious servers to steal browser and email client credentials, underscoring how leaked malware code can enable lower-skill actors while still producing a subset of credible financial threats.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
Kaspersky analyzed Jimmy, a new modular Trojan-banker/downloader delivered by a modified NeutrinoPOS malware family, and noted strong code overlap with the publicly available NukeBot source code. The malware shifted away from POS card theft to downloading modules for web injects and Monero mining.
Researchers also identified modified NukeBot variants that lacked web injection functionality and instead stole browser and mail client passwords. These variants were delivered inside droppers that downloaded credential-recovery utilities such as Email Password Recovery from malicious servers.
Researchers later identified several operational or "combat-grade" NukeBot versions. Analysis of the collected injects showed the primary targets were French and U.S. banks, and only about 2% to 5% of obtained samples were assessed as combat-ready.
By imitating bot-to-C2 interaction, researchers triggered NukeBot servers to send web injects and collected inject data from many servers. Most botnets initially served only test injects that matched examples included in the published source code.
After the source code became public, researchers obtained multiple compiled NukeBot samples. Most were non-operational test builds using localhost or local subnet command-and-control addresses, while a smaller subset used real C2 infrastructure.
The author of the NukeBot banking Trojan published its source code in the spring, reportedly to restore his reputation on hacker forums after being suspected of scamming. This release triggered subsequent analysis of compiled samples and later operational use by others.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
arbornetworks.com
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourcekrebsonsecurity.com
Open sourcesecurityintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.