Attackers manipulated Google search results for banking- and finance-related queries to steer victims to malicious links that ultimately delivered the Zeus Panda banking trojan. The campaign relied on SEO poisoning and chains of compromised websites and intermediary redirectors, with victims served a malicious Microsoft Word document that used macros to download and execute a PE32 payload. Reported targeting focused on users seeking financial institutions and banking information, particularly in India and parts of the Middle East.
Once installed, Zeus Panda used multiple anti-analysis and anti-sandbox checks, including CIS-region keyboard locale detection, hypervisor and security-tool discovery, exception-based unpacking, and self-deletion behavior. The malware established persistence through a Windows Run registry key and copied itself into a Flash Player-themed directory under the victim’s roaming profile, while associated reporting tied the activity to broader Zeus Panda tradecraft and infrastructure including malicious domains, hashes, distribution URLs, and command-and-control servers.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Cisco Talos reported a malware distribution campaign that used search engine optimization poisoning to place malicious links in Google results for banking- and finance-related searches, ultimately delivering the Zeus Panda banking trojan via malicious Word documents and macros. The report also disclosed technical details of the infection chain, anti-analysis behavior, persistence mechanisms, and indicators of compromise tied to the campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 44 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.