BackSwap
- First seen
- 2018-01-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:47:47
Targeted industries: financial-services
Targeted regions: country_code:pl country_code:es country_code:de
Context
BackSwap is a banking trojan known for its unique technique of injecting malicious scripts into web pages by replacing a code snippet related to web browser events. This malware has primarily targeted financial institutions in Europe, aiming to steal banking credentials from unsuspecting victims.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Backswap_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Backswap (report)
- research.checkpoint.com — The Evolution Of Backswap (report)
- securityintelligence.com — Backswap Malware Now Targets Six Banks In Spain (report)
- f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
- cyberbit.com — Backswap Banker Malware Hides Inside Replicas Of Legitimate Programs (report)
- ESET — Backswap Malware Empty Bank Accounts (report)
- explore.group-ib.com — Hi Tech Crime 2018 (report)
- fintechsecurity.com.hk — 01.Dmitry Annual Group Ib Report High Tech Crime Trends (report)
- cert.pl — Backswap Malware Analysis (report)
- cyberbit.com — Backswap Banker Malware Hides Inside Replicas Of Legitimate Programs (report)
- f5.com — Backswap Defrauds Online Banking Customers Using Hidden Input Fi (report)