Cinobi
- First seen
- 2019-08-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-13 01:01:37
- Profile updated
- 2026-07-07 14:52:45
Targeted industries: financial-services
Targeted regions: country_code:jp
Context
Cinobi is a banking trojan primarily targeting financial institutions in Japan. It is known for its ability to steal credentials and perform web injection attacks to gather sensitive information from online banking users.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Cinobi_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Cinobi (report)
- Trend Micro — Operation Overtrap Targets Japanese Online Banking Users Via Bottle Exploit Kit And Brand New Cinobi Banking Trojan (report)
- pwncode.io — Unpacking Payload Used In Bottle Ek (report)
- Trend Micro — Cinobi Banking Trojan Targets Users Of Cryptocurrency Exchanges (report)
- Trend Micro — Tech%20Brief Operation%20Overtrap%20Targets%20Japanese%20Online%20Banking%20Users (report)