Skip to content

Malware

Tinba

aka Zusy · TinyBanker · Illi

F-Secure notes that TinyBanker or short Tinba is usually distributed through malvertising (advertising content that leads the user to sites hosting malicious threats), exploit kits and spam email camp

Tinba, also known as Zusy, TinyBanker, Illi, is a Windows malware family.

Background

According to F-Secure, TinyBanker, or Tinba for short, typically spreads via malvertising (ad content that steers users toward sites hosting malicious payloads), exploit kits, and spam email campaigns. News coverage has reported Tinba targeting bank customers across the United States and Europe.

When Tinba manages to infect a device, it can harvest banking and personal data using webinjects. It watches the user's browsing, and when they open certain banking portals, it injects code that presents bogus web forms imitating the real site, coaxing the victim into typing personal details, login credentials, and similar information into the convincing-looking page.

Tinba can also surface socially engineered messages to entice or pressure the user into submitting their data on the fake page. One example is a message claiming that money was mistakenly deposited into the victim's account and must be paid back at once.


Source: Malpedia (Fraunhofer FKIE).