Zusy

Category: banking_trojan · Aliases: tinba, tinybanker, illibanker · Sample count (EMBER 2018): 14,120 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Zusy, also known as Tinba (Tiny Banker), is a notably compact banking trojan that gained attention for its small footprint of roughly 20KB while still implementing full webinject and form-grabbing capability. First seen around 2012, Zusy primarily targeted European banking customers through phishing and exploit kits. Its small size made detection harder and demonstrated that effective banking trojans did not require large code bases. The leaked Tinba source code spawned numerous derivative campaigns.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1185 T1071.001

Frequently Asked Questions

What is Zusy?

Zusy, also known as Tinba (Tiny Banker), is a notably compact banking trojan that gained attention for its small footprint of roughly 20KB while still implementing full webinject and form-grabbing capability. First seen around 2012, Zusy primarily targeted European banking customers through phishing and exploit kits. Its small size made detection harder and demonstrated that effective banking trojans did not require large code bases. The leaked Tinba source code spawned numerous derivative campaigns.

How does Zusy spread?

Zusy is an alias for Tinba and spreads through the same exploit kits, phishing campaigns, and malvertising used by the Tiny Banker family.

What are the signs of a Zusy infection?

Browser web-injects on banking sites, prompts for additional 2FA codes, and AV detections for Zusy, Tinba, or TinyBanker are diagnostic.

What should I do if I think I have Zusy on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/zusy.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.