MiniPanzer is a Swiss government surveillance trojan (a Bundestrojaner, or “federal Trojan horse”) and a variant alongside MegaPanzer. It was written in C++ by Ruben Unteregger for ERA IT Solutions, a contractor to the Swiss federal government. Reporting in the provided content states that Switzerland’s Federal Department of Environment, Transport, Energy and Communications (UVEK) later used MiniPanzer to intercept Skype and other voice-over-IP traffic on Windows XP systems. The malware runs on Windows x86 and has been described as using DLL injection. The source code was released under GPLv3 by Unteregger, with copyright retained, and was hosted on SourceForge; after that release, the trojan was reportedly detected in the wild. Anti-virus vendors identified at least one designation for the malware as Trojan.Peskyspy. The content does not provide specific hashes, domains, or other concrete IOC values beyond that AV naming and the DLL injection behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware referenced in the related 'See also' section without further detail in the content.
See also ... MiniPanzer and MegaPanzer
A Windows spyware trojan developed for lawful interception/surveillance, designed to intercept Skype and other VoIP traffic on Windows XP systems and using DLL injection.
See also ... MiniPanzer and MegaPanzer ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.