logo

Tinba Banking Trojan Variant

ID: 12b51434-403f-5587-8a8a-9db2b4af311d

STIX ID: report--12b51434-403f-5587-8a8a-9db2b4af311d

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Tinba is a small banking Trojan that injects into system and browser processes to harvest browsing data, login credentials and banking information; it persists by copying itself to a hidden folder under %APPDATA% and adding an autorun registry entry, uses a domain-generation algorithm (DGA) with fast-flux C2 infrastructure and simple XOR-based encryption for C2 communications, and is delivered via spam, drive-by downloads and exploit kits—this report provides behavioral analysis, unpacking details, TTPs and IOCs (domains and IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.