Panda Stealer is a Windows information-stealing malware family first observed in 2021 and primarily associated with theft of cryptocurrency wallet data and other user credentials. It has been described as a modified fork or variant of Collector Stealer and is notable for using fileless and in-memory execution techniques to reduce on-disk artifacts and evade detection.
Observed delivery has relied on spam email campaigns, including malicious Excel attachments that either use macros to download a loader or formulas that launch PowerShell. Follow-on stages have used paste-hosted content, PowerShell-based retrieval and decoding, direct in-memory loading of obfuscated .NET assemblies, and process hollowing of a legitimate Microsoft build utility process to execute the final stealer payload.
Panda Stealer targets cryptocurrency-related data including wallet private keys and transaction histories, and it has been reported stealing data from wallets associated with multiple major cryptocurrencies. Beyond wallet theft, it can collect browser-stored information such as cookies, saved passwords, and payment card data; capture screenshots; and steal credentials from applications including VPN, messaging, gaming, and social platforms. Stolen data is staged in temporary files and then exfiltrated to attacker-controlled infrastructure.
The malware has been observed in broad spam waves affecting multiple countries, including the United States, Australia, Japan, and Germany. Infrastructure analysis has linked Panda Stealer activity to numerous command-and-control servers and download sites, and some reporting has noted use of crypter services during testing or deployment. Panda Stealer has also appeared as a payload delivered by other malware distribution mechanisms, including RATDispenser. Its combination of credential theft, cryptocurrency-focused collection, fileless execution, and process hollowing makes it a capable infostealer oriented toward financially motivated intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The loaded assembly, obfuscated with an Agile.NET obfuscator... the hex-encoded Panda Stealer binary
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
画像・テキスト共有サイト悪用の参考例としてのみ挙げられている情報窃取型マルウェア。
A stealer targeting cryptocurrency wallets; the samples discussed were fileless variants that downloaded additional payloads from paste.ee, and were delivered by RATDispenser.
An information stealer delivered via spam emails and fileless infection chains. It steals cryptocurrency wallet data including private keys and transaction records, browser cookies/passwords/cards, screenshots, and credentials from applications such as NordVPN, Telegram, Discord, and Steam, then exfiltrates the data to C2 servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.