Online source code of the smallest banker Trojan Tinba

The source code of its first version Tinba, the smallest bank ever developed, is released online.

Tinba

Malicious software is also known as Tinybanker or zusy, and is only 20KB. It was first discovered in the middle of 2012 when it targeted specific people in Turkey. Then more than 60.000 unique infections were detected.

What immediately drew the attention of the security researchers who discovered it was its small size and its great functionality that competes with much larger Trojans.

Researchers from the CSIS Security Group, in Denmark, discovered a post on a closed underground forum. After careful , found that the source code contained in the post was for the first version of the malware released in 2011-2012.
Read more about Tinba from paper (PDF) by Trend Micro.

Tinba is created to spy on the program and to collect login information. Despite being only 20KB in size, the malware uses man-in-the-browser (MitB) and web-injection techniques to intercept and send data to its creator. This activity is usually carried out by special and complex malware.
The release of the source code to increases the risk of new trojans that are based in part on Tinba's source code.
The code is accompanied by full documentation and it looks like all of its developers are published. CSIS researchers note that everything is very well structured and that during their analysis they were able to compile the code without any problems.

Once the malware is installed, it develops a fuzzy injection routine that allows it to avoid detection by antivirus.

Researchers say it was possible to turn off the phishing web alarm in Mozilla Firefox so that the user does not suspect anything if he surfs on infected sites.

The communication with the administration server and it is encrypted with RC4 and used in a series of four domains. These it tries to contact to send information and pings until it gets a response.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).