TinyNuke
Aliases: MicroBankingTrojan, Nuclear Bot, NukeBot, Xbot
- First seen
- 2016-01-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-21 03:01:43
- Profile updated
- 2026-07-07 13:45:22
Targeted industries: financial-services
Context
TinyNuke (aka Nuclear Bot) is a fully-fledged banking trojan including HiddenDesktop/VNC server and a reverse socks4 server. It was for sale on underground marketplaces for $2500 in 2016. The program's author claimed the malware was written from scratch, but that it functioned similarly to the ZeuS banking trojan in that it could steal passwords and inject arbitrary content when victims visited banking Web sites. However, he then proceeded to destroy his own reputation on hacker forums by promoting his development too aggressively. As a displacement activity, he published his source code on Github. XBot is an off-spring of TinyNuke, but very similar to its ancestor.
Detection coverage
- 2 YARA rules
Used by threat actors
- Kimsuky (threat-actor)
Detection rules
- MALPEDIA_Win_Xbot_Pos_Auto (yara-rule)
- MALPEDIA_Win_Tinynuke_Auto (yara-rule)
Related threat objects
- Xbot (malware)
Reports & references
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- asec.ahnlab.com — 32781 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Tinynuke (report)
- krebsonsecurity.com — Nuclear Bot (report)
- arbornetworks.com — Dismantling Nuclear Bot (report)
- bitsighttech.com — Break Out Of The Tinynuke Botnet (report)
- krebsonsecurity.com — Nuclear Bot Author Arrested In Sextortion Case (report)
- forums.juniper.net — 326702 (report)
- asec.ahnlab.com — 27346 (report)
- Kaspersky — 78957 (report)
- benkowlab.blogspot.de — Quick Look At Another Alina Fork Xbot (report)
- securityintelligence.com — The Nukebot Trojan A Bruised Ego And A Surprising Source Code Leak (report)