BackSwap

First seen
2018-01-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Profile updated
2026-07-07 14:47:47

Targeted industries: financial-services

Targeted regions: country_code:pl country_code:es country_code:de

Context

BackSwap is a banking trojan known for its unique technique of injecting malicious scripts into web pages by replacing a code snippet related to web browser events. This malware has primarily targeted financial institutions in Europe, aiming to steal banking credentials from unsuspecting victims.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Backswap_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Backswap (report)
  • research.checkpoint.com — The Evolution Of Backswap (report)
  • securityintelligence.com — Backswap Malware Now Targets Six Banks In Spain (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • cyberbit.com — Backswap Banker Malware Hides Inside Replicas Of Legitimate Programs (report)
  • ESET — Backswap Malware Empty Bank Accounts (report)
  • explore.group-ib.com — Hi Tech Crime 2018 (report)
  • fintechsecurity.com.hk — 01.Dmitry Annual Group Ib Report High Tech Crime Trends (report)
  • cert.pl — Backswap Malware Analysis (report)
  • cyberbit.com — Backswap Banker Malware Hides Inside Replicas Of Legitimate Programs (report)
  • f5.com — Backswap Defrauds Online Banking Customers Using Hidden Input Fi (report)

External references