Tinba

Category: banking_trojan · Aliases: tinybanker, zusy, illibanker · Sample count (EMBER 2018): 1,531 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Tinba (Tiny Banker) is one of the smallest banking trojans publicly documented, with a footprint around 20KB that nonetheless implements full webinject, form-grabbing, and man-in-the-browser capabilities. It primarily targeted European banking customers from 2012 onward, and the leaked Tinba source code spawned multiple derivative campaigns. Tinba is often classified alongside or as Zusy by various AV vendors.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1185 T1071.001 T1055

Frequently Asked Questions

What is Tinba?

Tinba (Tiny Banker) is one of the smallest banking trojans publicly documented, with a footprint around 20KB that nonetheless implements full webinject, form-grabbing, and man-in-the-browser capabilities. It primarily targeted European banking customers from 2012 onward, and the leaked Tinba source code spawned multiple derivative campaigns. Tinba is often classified alongside or as Zusy by various AV vendors.

How does Tinba spread?

Tinba (Tiny Banker) is one of the smallest banking trojans (~20KB) and spreads through exploit kits, phishing, and malvertising campaigns.

What are the signs of a Tinba infection?

Browser web-injects on banking sites, prompts for additional credentials or 2FA codes, and antivirus references to Tinba, TinyBanker, or Zusy are signature indicators.

What should I do if I think I have Tinba on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/tinba.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.