{
  "family": "zusy",
  "sample_count": 14120,
  "category": "banking_trojan",
  "description": "Tinba (a contraction of 'Tiny Banker', also known as Zusy, TinyBanker, and Illi) is a Windows banking trojan. As documented by Malpedia (Fraunhofer FKIE), citing F-Secure, it is usually distributed through malvertising, exploit kits, and spam email campaigns, and has targeted bank customers in the United States and Europe. Once it infects a device, Tinba steals banking and personal information using webinjects: it monitors the user's browser activity and, when specific banking portals are visited, injects code that presents fake web forms mimicking the legitimate site to trick the victim into entering credentials and personal data. Tinba may also display socially engineered messages to pressure the user into entering information — for example, claiming that funds were accidentally deposited and must be refunded immediately. Tinba is notable for its very small code footprint, which is the origin of its 'Tiny Banker' name.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "tinba",
    "tinybanker",
    "illibanker"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is Tinba?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Tinba, short for 'Tiny Banker' and also known as Zusy or TinyBanker, is a Windows banking trojan. According to Malpedia, citing F-Secure, it steals banking and personal information from infected computers, and has targeted bank customers in the United States and Europe."
      }
    },
    {
      "@type": "Question",
      "name": "How does Tinba spread?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Per Malpedia, citing F-Secure, Tinba is usually distributed through malvertising (malicious advertising that leads users to sites hosting threats), exploit kits, and spam email campaigns."
      }
    },
    {
      "@type": "Question",
      "name": "How does Tinba steal banking credentials?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Tinba uses a technique called webinjects. It monitors the user's browser activity, and when the victim visits specific banking portals, it injects code that displays fake web forms designed to mimic the legitimate site, tricking the victim into entering their login credentials and personal information."
      }
    },
    {
      "@type": "Question",
      "name": "What social engineering does Tinba use?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Malpedia notes that Tinba may display socially engineered messages to lure or pressure victims into entering information on its fake pages. One example cited is a message claiming that funds were accidentally deposited into the victim's account and must be refunded immediately."
      }
    },
    {
      "@type": "Question",
      "name": "Why is Tinba called 'Tiny Banker'?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The name Tinba is a contraction of 'Tiny Banker', a reference to the malware's unusually small code size. Malpedia lists it under the symbol win.tinba with the aliases Zusy, TinyBanker, and Illi."
      }
    }
  ],
  "faq_count": 5,
  "mitre_attack": [
    "T1185",
    "T1071.001"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-06-10",
  "sources": [
    {
      "name": "Malpedia (Fraunhofer FKIE): Tinba (win.tinba)",
      "url": "https://malpedia.caad.fkie.fraunhofer.de/details/win.tinba"
    }
  ],
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}