Netskope Threat Labs

Tinba

ATP Sandbox Adv. Heuristics

Tinba (a.k.a. TinyBanker) is a banking trojan that steals financial credentials through web injection techniques while remaining small enough to fit in memory with almost no footprint. It injects code into banking websites to capture logins, and it uses man in the middle tactics to manipulate transactions without alerting victims. Its source code leaked in 2014, spawning many variants, and the family's technical elegance has kept it a subject of study among banking trojans.

First seen
May 2023
Last seen
October 2026
Alert Name
Binary.Infostealer.Tinba
ByteCode-MSIL.Infostealer.Tinba
Document-HTML.Infostealer.Tinba
Document-Multimedia.Infostealer.Tinba
Document-RTF.Infostealer.Tinba
Package.Infostealer.Tinba
Script-AutoIt.Infostealer.Tinba
Script-BAT.Infostealer.Tinba
Script-JS.Infostealer.Tinba
Script-PowerShell.Infostealer.Tinba