PandaBanker is a Windows banking trojan associated with financially motivated cybercrime operations. It has been linked to large-scale criminal infrastructure used for phishing, malware distribution, and online banking fraud, including the Avalanche ecosystem. Available reporting indicates that PandaBanker used dynamic botnet configuration data and server-based infrastructure to retrieve additional files, consistent with staged payload delivery and modular operation. It has been tracked in multiple botnet variants and versioned configurations during 2018, suggesting active maintenance and operational customization.
PandaBanker has primarily been associated with campaigns targeting financial institutions and users of online banking services. Its inclusion alongside other banking malware families in major criminal distribution networks supports its role in credential and financial-data theft. The malware targets Microsoft Windows systems and appears to rely on external infrastructure for follow-on payload retrieval or updates. PandaBanker has also been observed on infrastructure used to host numerous malware families, indicating use within broader crimeware-as-a-service or shared hosting ecosystems.
High-confidence public information in this dataset does not establish a fuller capability set beyond its banking-trojan role, Windows targeting, and use of dynamic configuration to download additional files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The criminal groups have been using the Avalanche infrastructure since 2009 for conducting malware, phishing and spam activities. They sent more than 1 million e-mails with damaging attachments or links every week to unsuspecting victims.
Sinkholing is an action whereby traffic between infected computers and a criminal infrastructure is redirected to servers controlled by law enforcement authorities... infected computers can no longer reach the criminal command and control computer systems and so criminals can no longer control the infected computers.
Active since 2009, the Avalanche botnet has been used for money muling schemes, distributing a wide variety of malware, and as a fast-flux communication infrastructure for other botnets.
What made the ’Avalanche’ infrastructure special was the use of the so-called double fast flux technique. The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
Mentioned as one of the malware families descended from Zeus.
Banking trojan listed among malware families hosted by Avalanche.
Banking trojan listed among malware hosted by Avalanche.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.