PandaZeuS
Panda Banker, also known as PandaZeus, is an e-banking Trojan derived from the ZeuS codebase and used by multiple cybercriminal actors to steal online banking credentials and facilitate banking fraud.
PandaZeuS
Family profile
Panda Banker, also known as PandaZeus, is an e-banking Trojan derived from the ZeuS codebase and used by multiple cybercriminal actors to steal online banking credentials and facilitate banking fraud. It targets Windows systems and has been observed in active campaigns aimed primarily at English-speaking users. The malware is associated with credential theft against online financial services and uses encrypted configuration data and command-and-control communications to support its operations.
Later observed variants, including version 2.6.1, retained AES-256-CBC and RC4-based protection for their base configuration while introducing a modified RC4 routine. This change appears intended to hinder automated analysis and extractor tooling used by defenders and researchers, indicating ongoing defense-evasion development. Panda Banker has also been observed using self-signed SSL/TLS certificates in its infrastructure, consistent with broader Zeus-family operational patterns.
Panda Banker is best characterized as a banking Trojan focused on compromising e-banking credentials rather than destructive or ransomware activity. It has been used across multiple campaigns and by different threat actors, reflecting its role as a reusable criminal malware family in the online banking fraud ecosystem.
Capabilities
- Credential Theft
- Defense Evasion
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
MITRE ATT&CK