Researchers reported that Panda Stealer is being distributed through spam emails carrying malicious Excel attachments and is designed to steal cryptocurrency wallet data, browser information, screenshots, and credentials from applications including NordVPN, Telegram, Discord, and Steam. The malware was described as a modified fork of Collector Stealer and was observed targeting victims in the United States, Australia, Japan, and Germany during a broad spam wave.
The malware uses fileless and evasive techniques to avoid detection, including PowerShell, payload hosting on paste.ee, in-memory loading of a .NET assembly, and process hollowing of MSBuild.exe. Investigators also linked the operation to multiple command-and-control and download servers, and said testing activity suggested use of a Shock Hosting VPS and Cassandra Crypter, indicating a coordinated credential- and wallet-theft campaign focused on monetizing stolen crypto assets and account access.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Trend Micro observed Panda Stealer being delivered through spam emails in early April 2021. The malware was identified as an information stealer targeting cryptocurrency wallets and other credentials.
Trend Micro disclosed technical details on Panda Stealer, including its fileless Excel and PowerShell infection chains, in-memory .NET loading, process hollowing of MSBuild.exe, and links to more than 140 C2 servers and over 10 download sites. The report also noted affected countries and similarities to Collector Stealer.
Shock Hosting confirmed that the server assigned to an IP address believed by researchers to have been used by the Panda Stealer actor for testing had been suspended. The IP was linked to an active Panda Stealer C2 server during the investigation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 53 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.