Sinowal
Aliases: Anserin, Mebroot, Quarian, Theola, Torpig
- First seen
- 2006-01-01 00:00:00
- Malware type
- credential-stealer, botnet, rootkit
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:33:56
- Profile updated
- 2026-07-07 13:03:55
Targeted industries: financial-services
Context
Sinowal, also known as Torpig or Mebroot, is a sophisticated banking Trojan known for stealing credentials from financial institutions. It operates with rootkit capabilities to remain undetected on infected systems.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Sinowal_Auto (yara-rule)
Related threat objects
- Torpig (infrastructure)
Reports & references
- Kaspersky — 97937 (report)
- web.archive.org — Globalthreatintelreport (report)
- malware.dontneedcoffee.com — Eyeglanceru (report)
- web.archive.org — Blackhat Eu 2010 Carrera Silberman State Of Malware Slides (report)
- media.kasperskycontenthub.com — Bartholomew Guerrerosaade Vb2016 (report)
- recordedfuture.com — Turla Apt Infrastructure (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sinowal (report)
- Wikipedia — Torpig (report)
- virusbulletin.com — Sinowal Banking Trojan (report)
- ESET — How Theola Malware Uses A Chrome Plugin For Banking Fraud (report)
- Broadcom/Symantec — Writeup.Jsp (report)