TinyNuke, also known as Nuclear Bot, is a Windows banking trojan first identified in 2016. It is associated with credential-focused financial crime activity and is known for combining banking malware functions with remote-control capabilities. Documented features include form grabbing, Hidden VNC (HVNC) for covert graphical remote access, and a reverse SOCKS4 proxy. Its source code became public in 2017, which enabled code reuse and adaptation by other malware developers and operators.
TinyNuke has been used to target online banking customers, including campaigns against French and Polish banks. Reporting has linked custom TinyNuke variants to financially motivated operators in France, with some versions reportedly extended beyond the public codebase. The malware family is also notable for its HVNC implementation, which allows attackers to interact with an infected system in a hidden desktop session without exposing the activity to the local user. Reverse VNC-style connectivity has also been observed, enabling the compromised host to initiate the connection outward and thereby easing operation across NAT and firewall boundaries.
Beyond direct criminal use, TinyNuke has influenced later malware families through code borrowing, especially around HVNC and proxy functionality. BitRAT and AveMaria have both been reported to reuse TinyNuke-derived code. North Korea-linked Kimsuky activity has also been observed deploying TinyNuke-derived HVNC capability as a post-compromise remote-control component alongside AppleSeed and other tooling, with observed use focused on the HVNC feature rather than the full banking feature set.
TinyNuke targets Windows systems and is best characterized as banking malware with additional remote-access and post-compromise utility. Its known behaviors support credential theft, covert remote interaction, and data capture from web sessions, making it relevant both as a standalone financial malware family and as a code lineage that has shaped subsequent commodity RAT and HVNC ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Note that BitRAT uses the revealed TinyNuke’s code, just like AveMaria.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
A difference between normal VNC and HVNC used by TinyNuke is that the user does not realize that the PC is infected and its screen is being controlled... the GUI of the process created while the attacker is controlling the target PC is not visible on the target PC screen.
When first contacting a C&C, the bot is sent an RC4 key which it uses to decrypt injections.
Another characteristic is that it uses the reverse VNC method... HVNC of TinyNuke attempts to access the client from the server with the reverse VNC feature.
TinyNuke, also known as Nuclear Bot, is a banking malware discovered in 2016. It includes features such as HVNC (HiddenDesktop/VNC), reverse SOCKS4 proxy, and form grabbing.
We received those samples exclusively within droppers: after unpacking, they downloaded the required utilities (such as ‘Email Password Recovery’) from a remote malicious server.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BitRAT Disguised as Windows Product Key Verification Tool Being Distributed BitRAT TinyNuke
A malware family observed as a payload in StealC-related delivery chains.
TinyNuke was observed as a payload in StealC-related operations.
Banking malware whose HVNC capability is selectively enabled and reused by Kimsuky for remote control of infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.