Note that BitRAT uses the revealed TinyNuke’s code, just like AveMaria.
TinyNuke
TinyNuke, also known as Nuclear Bot, is a Windows banking trojan first identified in 2016.
Profile source: Mallory opens in a new tabTinyNuke
Family profile
TinyNuke, also known as Nuclear Bot, is a Windows banking trojan first identified in 2016. It is associated with credential-focused financial crime activity and is known for combining banking malware functions with remote-control capabilities. Documented features include form grabbing, Hidden VNC (HVNC) for covert graphical remote access, and a reverse SOCKS4 proxy. Its source code became public in 2017, which enabled code reuse and adaptation by other malware developers and operators.
TinyNuke has been used to target online banking customers, including campaigns against French and Polish banks. Reporting has linked custom TinyNuke variants to financially motivated operators in France, with some versions reportedly extended beyond the public codebase. The malware family is also notable for its HVNC implementation, which allows attackers to interact with an infected system in a hidden desktop session without exposing the activity to the local user. Reverse VNC-style connectivity has also been observed, enabling the compromised host to initiate the connection outward and thereby easing operation across NAT and firewall boundaries.
Beyond direct criminal use, TinyNuke has influenced later malware families through code borrowing, especially around HVNC and proxy functionality. BitRAT and AveMaria have both been reported to reuse TinyNuke-derived code. North Korea-linked Kimsuky activity has also been observed deploying TinyNuke-derived HVNC capability as a post-compromise remote-control component alongside AppleSeed and other tooling, with observed use focused on the HVNC feature rather than the full banking feature set.
TinyNuke targets Windows systems and is best characterized as banking malware with additional remote-access and post-compromise utility. Its known behaviors support credential theft, covert remote interaction, and data capture from web sessions, making it relevant both as a standalone financial malware family and as a code lineage that has shaped subsequent commodity RAT and HVNC ecosystems.
Capabilities
- Credential Theft
- Defense Evasion
- Post Exploitation
- Session Hijacking
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK