Zeus Panda Banker is a banking trojan observed as follow-on malware delivered by other malware families. In the provided content, it is explicitly identified as a payload commonly seen during Emotet infections in lab environments, and as a follow-up malware family historically delivered by Hancitor malspam campaigns until November 2018, when Hancitor switched to Ursnif. The content therefore associates Zeus Panda Banker with loader/distribution activity by both Emotet and Hancitor rather than describing its standalone infection chain. The available material does not provide direct technical details on Zeus Panda Banker’s internal capabilities, persistence mechanisms, targeted sectors, or specific indicators of compromise. High-confidence context from the content is limited to its role as banking malware used as a secondary payload in Windows-focused infection chains involving Emotet and Hancitor malspam operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan previously delivered as a follow-on payload by Hancitor until Nov 2018.
Referenced as a banking trojan family observed as a follow-on payload in Emotet infection chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.