The source code of the first version of Tinba, the smallest banking Trojan ever developed, is released online.
The malware is also known as Tinybanker or zusy, and it is only 20KB. It was first discovered in mid-2012, when it targeted specific individuals in Turkey. At that time more than 60,000 unique infections were identified.
What immediately caught the attention of the security researchers who discovered it was its small size and its great functionality that competes with much larger Trojans.
Researchers from the CSIS Security Group in Denmark discovered a post on a closed underground forum. After careful analysis, they determined that the source code contained in the post was for the first version of the malware, which was released in 2011-2012.
Read more about Tinba in the Trend Micro paper (PDF).
Tinba is designed to spy on the browser and collect login credentials. Despite being only 20KB in size, the malware uses man-in-the-browser (MitB) and web-injection techniques to intercept and send data to its creator. This activity is usually carried out by specialized and sophisticated malware.
The release of the source code on the Internet increases the risk of new trojans that are based in part on the Tinba source code.
The code is fully documented and appears to have been fully published by its developers. CSIS researchers note that everything is very nicely structured and that during their analysis, they were able to compile the code without any problems.
Once the malicious software is installed, it develops an obscure injection routine that allows it to evade detection by antivirus.
Researchers report that among its capabilities was disabling the fake site alarm in Mozilla Firefox, so that the user would not suspect anything when browsing infected sites.
Communication with the management and control server is encrypted with RC4 and uses a series of four domains. It tries to communicate with them to send information and pings until it receives a response.

