Panda Banker, also known as ZeuS Panda, Zeus Panda, and PandaBot, is a Windows banking trojan derived from the Zeus malware lineage. Active at least from 2016 through the end of 2018, it was used in both targeted intrusions and broader criminal distribution campaigns. The malware was observed in email-borne attacks using malicious Microsoft Office documents, including exploit-based attachments and macro-enabled downloaders, and was also distributed through multiple exploit kits and malvertising-driven traffic. Threat actors associated with its delivery included TA511 and TA544, and it was also delivered as a secondary payload by Emotet in some campaigns.
Panda Banker is designed to steal banking credentials and related financial data using man-in-the-browser techniques and webinjects. Its configurations have targeted banks and financial institutions in multiple regions, including Australia, the United Kingdom, Italy, and Japan. Campaigns against Japanese financial institutions used numerous webinjects, many focused on banking and credit-card workflows. The malware can receive encrypted or obfuscated configuration data from command-and-control infrastructure, including webinject content and JavaScript used to support automated fraud workflows.
The malware exhibits strong Zeus-family tradecraft, including similar persistence mechanisms, mutex usage, registry-based installation behavior, and browser-focused credential theft. It collects host telemetry from infected systems and communicates with command-and-control servers using structured, obfuscated data formats. Panda Banker also supports modular functionality, including remote-access and proxy capabilities through VNC and SOCKS components, enabling operators to conduct fraudulent transactions from victim systems and extend post-compromise control.
Operationally, Panda Banker has been distributed through malicious email attachments, exploit kits such as Angler, Nuclear, Neutrino, and RIG, and intermediary loaders including GODZILLA. Some campaigns used geographic filtering to restrict infections to selected countries. Its infrastructure has also employed resilience measures such as fast-flux DNS. Overall, Panda Banker was a prominent Zeus-derived banking malware family used by financially motivated actors for credential theft and online banking fraud across multiple regions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On March 10, we detected a targeted email with a Microsoft Word attachment ... It exploits the vulnerabilities CVE-2014-1761 and CVE-2012-0158. | We have observed the malware, dubbed "Panda Banker", being used for targeted attacks via email attachments. We are also tracking its use in broad attacks via at least 3 different exploit kits (EKs).
On March 10, we detected a targeted email with a Microsoft Word attachment ... It exploits the vulnerabilities CVE-2014-1761 and CVE-2012-0158. | We have observed the malware, dubbed "Panda Banker", being used for targeted attacks via email attachments. We are also tracking its use in broad attacks via at least 3 different exploit kits (EKs).
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In approximately November 2017, TA511 switched from ZLoader to Panda Banker.
In approximately November 2017, TA511 switched from ZLoader to Panda Banker.
Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
Proofpoint researchers began tracking an actor (referred to as TA544) in February of 2017 when reports first emerged about malicious email campaigns targeting Italian customers using the Panda Banker malware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
We are also tracking its use in broad attacks via at least 3 different exploit kits (EKs).
Proofpoint researchers observed email campaigns widely distributing a new version of the ZLoader banking malware... The fraudulent email lures include a variety of subjects, including COVID-19 scam prevention tips, COVID-19 testing, and invoices.
Fake resume document attachment contains macros that, if enabled, launch PowerShell code to download Zeus Panda.
On March 19, we detected a targeted email with a Microsoft Word attachment... that used an Xbagging (aka Bartallex) downloader macro.
While PandaZeuS is still using the RC4 binary encryption scheme, it comes with some tiny modifications... we suspect the intent behind this code change is to break malware extractors used by malware researchers to extract botnet controllers from PandaZeuS malware samples.
these injects collected the credit card number, address, phone number, DOB, SSN, and security question-related information such as mother’s maiden name.
these injects collected the credit card number, address, phone number, DOB, SSN, and security question-related information such as mother’s maiden name.
We also observed the following “webinjects” being used, targeting Australian and UK banks.
81 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point for how Matrix Banker might evolve.
Referenced in passing as banking malware previously distributed through Godzilla Loader.
PC banking trojan listed among malware actively used to attack companies.
Banking trojan distributed by TA544 as part of financially motivated campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.