Netskope Threat Labs

Zusy

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Zusy (a.k.a. TinyBanker) is a banking trojan based on the Zeus source code that aims to steal personal information via code injection into websites. Its tiny footprint lets it hide in memory while it injects code into banking pages, capturing login details and payment data as victims enter them. Rather than attacking bank infrastructure directly, it targets the customers of financial institutions, and leaked source code has kept variants circulating for over a decade.

First seen
January 2022
Last seen
October 2026
zusy
Alert Name
Archive-RAR.Trojan.Zusy
Binary.Trojan.Zusy
ByteCode-MSIL.Trojan.Zusy
Gen:Variant.Adware.ICloader.Zusy.107
Gen:Variant.Adware.Neoreklami.Zusy.8
Gen:Variant.Adware.Zusy.189775
Gen:Variant.Adware.Zusy.189851
Gen:Variant.Adware.Zusy.189980
Gen:Variant.Adware.Zusy.309903
Gen:Variant.Adware.Zusy.310056