Panda Banker, also known as PandaZeus, is an e-banking Trojan derived from the ZeuS codebase and used by multiple cybercriminal actors to steal online banking credentials and facilitate banking fraud. It targets Windows systems and has been observed in active campaigns aimed primarily at English-speaking users. The malware is associated with credential theft against online financial services and uses encrypted configuration data and command-and-control communications to support its operations.
Later observed variants, including version 2.6.1, retained AES-256-CBC and RC4-based protection for their base configuration while introducing a modified RC4 routine. This change appears intended to hinder automated analysis and extractor tooling used by defenders and researchers, indicating ongoing defense-evasion development. Panda Banker has also been observed using self-signed SSL/TLS certificates in its infrastructure, consistent with broader Zeus-family operational patterns.
Panda Banker is best characterized as a banking Trojan focused on compromising e-banking credentials rather than destructive or ransomware activity. It has been used across multiple campaigns and by different threat actors, reflecting its role as a reusable criminal malware family in the online banking fraud ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
While PandaZeuS is still using the RC4 binary encryption scheme, it comes with some tiny modifications... we suspect the intent behind this code change is to break malware extractors used by malware researchers to extract botnet controllers from PandaZeuS malware samples.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An e-banking trojan associated with botnet controllers. The content notes that modern e-banking trojans like PandaZeuS still rely on leaked source code from the original ZeuS.
An e-banking trojan derived from ZeuS that steals online banking credentials and is used for e-banking fraud. The content also notes updates to its base configuration encryption scheme in version 2.6.1, likely intended to hinder malware analysis and extractor tools.
An e-banking trojan derived from ZeuS that steals online banking credentials and is used for e-banking fraud. The article focuses on recent campaigns and minor changes in its base config encryption scheme intended to hinder malware analysis and extractor tools.
Banking trojan family using SSL/TLS with self-signed certificates and multiple observed subject DN patterns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.