logo

Backswap malware analysis

ID: 0074b7d6-be57-5da5-95e6-1f0be04ab63b

STIX ID: report--0074b7d6-be57-5da5-95e6-1f0be04ab63b

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2018-06-19

Date Updated: 2026-04-19

Author: Hubert Barc

...
...

Backswap is a compact banking trojan (a TinBa variant) that targets primarily Polish banks and some cryptocurrency wallets by injecting JavaScript WebInjects, swapping clipboard account numbers, and exfiltrating credentials. The report analyzes its position-independent code, custom Windows API resolution (hashed function names), payload storage/xor in the PE .rsrc section, novel browser injection techniques (clipboard+developer console or simulated typing), event-hooking to capture credentials via window titles, and C2 behaviors; YARA rules, hashes and IoCs are referenced for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.