Researchers tracked Panda Banker—also known as PandaZeuS, a Zeus-derived banking trojan—across multiple campaigns that used phishing, malvertising, and exploit-kit delivery to infect Windows users and steal credentials through man-in-the-browser webinjects. Reports documented active variants from 2.6.1 through 2.6.10, including a Japanese campaign built around version 2.6.6 with 27 webinjects aimed largely at local banks and credit-card sites, as well as botnets and configs labeled ank, Onore2, Cosmos3, and 2.6.8. Operators also altered Panda’s configuration encryption, apparently to hinder malware extractors and obscure controller infrastructure.
Technical analyses showed Panda using staged JavaScript webinjects, backend-driven fraud workflows, screenshots, keylogging, clipboard theft, and VNC-related abuse to capture credentials and manipulate online banking sessions. The malware’s second-stage logic could identify login pages, exfiltrate victim data over HTTPS, display fake outage overlays, and guide victims into authorizing fraudulent transfers, effectively bypassing two-factor authentication through social engineering. By 2018, Panda had broadened beyond traditional financial targets to cryptocurrency exchanges, social media, email, ecommerce, entertainment, search, tech, and adult sites, while exposed administration panels and public config tracking highlighted a mature criminal operation with region-specific infrastructure tied to campaigns in Italy, Japan, the United States, and Latin America.

Pull IOCs and campaign context straight into your stack.
14 events from the most recent confirmed update back to the earliest known activity.
The public PandaBanker configuration repository showed repeated additions of dynamic config files across 2018, with the latest visible commit on October 9, 2018 adding more files via upload.
F5 Labs reported that it had analyzed four Panda campaigns active between February and May 2018 and noted that three campaigns active in May were still running at the time of writing.
In May 2018, Panda targeted Facebook and Twitter across all three active campaigns described in the report, reflecting expansion beyond traditional banking targets.
A third Panda campaign active in May 2018, labeled "Cosmos3," targeted financial institutions in Latin America, especially in Argentina, Colombia, and Ecuador.
On May 1, 2018, researchers identified two distinct Panda samples both labeled botnet "2.6.8": one focused mainly on US financial organizations and another aimed at Japanese financial institutions, each using different C2 infrastructure.
Researchers observed a Panda Banker 2.6.6 sample in the wild on March 26, 2018, in a campaign named "ank" targeting Japanese financial institutions; they said it was the first Panda activity they had seen aimed at Japanese organizations.
A public GitHub repository included PandaBanker dynamic configuration files dated from February 21, 2018 onward, showing multiple botnet versions and named variants being collected over time.
In February 2018, a Panda campaign labeled "Onore2" targeted Italian financial institutions and a broad set of cryptocurrency services worldwide, with cryptocurrency targeting relying heavily on screenshots rather than standard webinjects.
Spamhaus Malware Labs reported two PandaZeuS campaigns spread shortly before Christmas 2017 and said the latest observed version was 2.6.1, which introduced a modified RC4-based configuration encryption scheme.
Proofpoint reported that Zeus Panda campaigns observed since November 2017 expanded beyond banking to target online shopping, travel, retail, and streaming sites during the holiday season. The malware used tailored webinjects to steal payment card data and personal information, with phishing document campaigns observed on November 13 against Canadian companies and on December 11 against UK business users.
A March 2017 analysis described how Zeus Panda used backend-controlled state transitions such as SL, CP, TL, GD, and CG to manipulate online banking sessions and socially engineer victims into authorizing fraudulent transfers.
A February 2017 analysis documented Zeus Panda's multi-stage webinject workflow, including a generic first-stage loader, target-specific second-stage scripts, and an exposed administration panel used to review infected machines and stolen banking data.
In March 2016, Proofpoint observed Panda Banker in targeted email attacks, including campaigns on March 10 against mass media and manufacturing staff and on March 19 against financial-sector individuals. The report also documented Panda Banker delivery via Angler, Nuclear, and Neutrino exploit kits, with UK and Australia infections and Zeus-like banking Trojan functionality.
An update stated that the Japanese-targeting Panda campaign was being distributed through malvertising that redirected victims to the RIG exploit kit, which then delivered the malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 100 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcef5.com
Open sourcearbornetworks.com
Open sourcespamhaus.org
Open sourceproofpoint.com
Open sourcecyber.wtf
Open sourcecyber.wtf
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.