The Cinobi banking trojan was used in a long-running campaign targeting users in Japan, combining phishing emails, fake banking pages, and malvertising to steal credentials from online banking customers. Trend Micro linked the activity to Operation Overtrap and said the attackers used a custom Bottle Exploit Kit against Japanese-language Internet Explorer users, exploiting CVE-2018-15982 and CVE-2018-8174 before deploying Cinobi. The malware used a multi-stage infection chain with locale checks for Japanese systems, RC4-encrypted configuration files, a CMSTPLUA UAC bypass, persistence through a malicious Winsock provider, and later adopted Tor-based command-and-control communications.
Researchers later observed the same malware family evolve beyond browser exploits and traditional banking targets. In a newer malvertising campaign attributed to Water Kappa, victims in Japan were lured to download ZIP files disguised as porn games, reward-point apps, or video-streaming software; the infection chain used legitimate Logitech Capture components for DLL sideloading, with LogiCapture.exe loading a malicious Xjs.dll that decrypted shellcode from format.cfg and launched staged Cinobi payloads. Updated Cinobi configurations targeted 11 Japanese financial institutions, including at least three cryptocurrency trading services, showing that the operators had expanded from online banking theft to credential theft against cryptocurrency exchange users while continuing to restrict access to Japanese IP addresses and reuse related infrastructure.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Trend Micro telemetry cited in the report shows Bottle Exploit Kit was the most active exploit kit detected in Japan in February 2020.
On September 29, 2019, the exploit kit stopped dropping a clean binary and began delivering a newly identified banking trojan named Cinobi to victims.
In mid-September 2019, victims were redirected to the exploit kit after clicking links from social media platforms, showing an active malvertising-driven infection path.
The campaign was first discovered in September 2019 through activity involving a then-unidentified exploit kit used against Japanese users.
Trend Micro telemetry indicates the Operation Overtrap banking malware campaign had been active since at least April 2019, targeting online banking users in Japan through phishing and malvertising.
Researchers observed updated Cinobi configurations targeting 11 Japanese financial institutions, including at least three cryptocurrency trading services, marking an expansion from banking theft to cryptocurrency account credential theft.
Trend Micro reported a new campaign attributed to Water Kappa that delivered Cinobi through malicious ads and ZIP archives, moving beyond the earlier Internet Explorer-focused Bottle exploit kit approach.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 42 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.