Zeus Panda, also known as Panda Banker, is a Windows banking Trojan descended from the Zeus ecosystem and primarily used for credential theft and financial fraud through man-in-the-browser style web injection. It targets online banking sessions and has also been used against broader non-banking targets such as retail, travel, and streaming services to harvest payment card data, personal information, and authentication details during periods of heightened online shopping activity.
The malware is commonly delivered as a secondary payload and has been observed in email-borne campaigns using malicious Microsoft Word documents with macros that invoke PowerShell to download and execute the Trojan. Campaign lures have included job-application and package-delivery themes aimed at business users and enterprises.
On infected systems, Zeus Panda performs host reconnaissance, including checking running processes, collecting system time, and identifying installed antivirus, antispyware, or firewall products. It supports screenshot capture and keylogging, including by hooking keyboard-related functions. It establishes persistence through Registry Run keys and modifies Windows settings to weaken browser phishing protections. It also includes cleanup functionality to delete files or uninstall scripts in order to reduce forensic visibility.
A notable component of Zeus Panda is its multi-stage webinject framework. An initial obfuscated JavaScript loader identifies the victim browser, sets bot-specific configuration values, and retrieves target-specific second-stage code. The second stage inspects banking or payment pages, detects login states, intercepts credentials and form submissions, and can present deceptive overlays such as temporary outage messages while exfiltrating captured data to attacker-controlled infrastructure. Operational use has included backend administration panels for reviewing infected hosts, stolen credentials, victim account details, and fraud workflow notes.
Zeus Panda has been associated with financially motivated cybercrime operations rather than espionage activity. Its behavior reflects a mature banking malware platform combining credential interception, browser manipulation, surveillance, persistence, and defense evasion to support account takeover and payment fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On at least one occasion during the Christmas week, Emotet also downloaded Zeus Panda. This instance of Zeus Panda primarily targeted online retail sites during the holiday season.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The data is used by the CP branch to display a fake overlay with a message and/or images, to trick the victim into starting a transaction. To that end, the fake overlay is used like in a normal phishing attack.
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The malicious document receipt-package-5a0a062cae04a.doc contains macros that, if enabled, launched PowerShell code to download Zeus Panda.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
As usual, the JavaScript is protected by an obfuscation layer, which substitutes string and function names using the following mapping array
The content repeatedly describes malware and actors capturing user input through keylogging modules and hooks, including references to SetWindowsHookEx, TranslateMessage, WM_KEYDOWN, GetKeyState, and GetAsyncKeyState.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
The content repeatedly describes malware and actors capturing user input through keylogging modules and hooks, including references to SetWindowsHookEx, TranslateMessage, WM_KEYDOWN, GetKeyState, and GetAsyncKeyState.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
These webinjects are used to manipulate the functionality of the target online banking websites on the client.
gromnes[.]top Domain Panda C&C aklexim[.]top Domain Panda C&C kichamyn[.]top Domain Panda C&C
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
It simply downloads the malicious executable, saves it into the %TEMP% directory on the system using the filename such as "obodok.exe". | The intermediary server will then respond with a HTTP 302 which redirects clients to another compromised site which is actually being used to host a malicious Word document. As a result, the client will follow this redirection and download the malicious document. This is a technique commonly referred to as "302 cushioning"
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
65 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that uses PowerShell to download and execute its payload.
Software changes: ... Zeus Panda
Banking trojan that decrypts code strings during execution.
Malware that establishes persistence by creating Registry Run keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.