#TinyNuke
Malware/Tool
2021-09-27 • Kimsuky 그룹에서 사용하는 VNC 악성코드 (TinyNuke, TightVNC)
TinyNuke, also called Nuclear Bot, is banking malware first observed in 2016 that includes hidden VNC, reverse SOCKS4 proxy, and browser form-grabbing capabilities. Its source code became public around 2017, enabling use by multiple actors and reuse of some features by other malware. In the cited Kimsuky activity, TinyNuke was installed through the AppleSeed backdoor after initial compromise. The deployed build reportedly retained only the hidden VNC capability, giving Kimsuky graphical remote control of the infected system.
-
2
Tagged Reports
-
1
Unique Authors
-
24
Active Days