Panda, also known as Zeus Panda, is a Zeus-derived banking trojan first identified in 2016 and primarily targeting Windows systems. Built on the Zeus lineage, it is designed to steal financial and other web-based account data through browser-centric fraud techniques. Documented capabilities include man-in-the-browser activity, web injects, interception of keystrokes and form data, screenshot capture, clipboard theft, and abuse of remote-access functionality associated with VNC. Panda has also been noted for stealth and anti-analysis measures intended to hinder forensic examination and antivirus detection.
Although initially associated with banking theft, Panda expanded beyond traditional financial institutions to target cryptocurrency services, social media platforms, email and search providers, payroll services, ecommerce, entertainment, technology services, and other consumer web properties. Campaign reporting has shown geographically tailored targeting, including operations focused on Italy, the United States, Japan, and parts of Latin America.
Panda has been distributed through phishing campaigns and has also been delivered by other malware ecosystems, including Emotet. It remained active years after the original Zeus family emerged, illustrating the continued operational value of leaked Zeus code and its descendants in financially motivated cybercrime. Panda is also associated in some reporting with ShadowVoice infrastructure or administration panels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Carberp works like many other banking trojans by logging keystrokes, spoofing websites, and hiding instances of itself in specific locations.
Its main attack techniques include web injects, screen shots of user activity (up to 100 per mouse click)
The Trojan is distributed through spam, which it sends itself, and can spread over local networks and download other malware.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Panda/Zeus Panda is a banking trojan distributed by Emotet; the content says it performs man-in-the-browser attacks and intercepts keystrokes and web form input.
Zeus variant using MITB attacks, keylogging, and advanced stealth/anti-analysis capabilities; expanded beyond banks to cryptocurrency exchanges, social media, and web services.
Panda is identified as a banking trojan previously distributed by the same actor that briefly switched to DanaBot in the described campaign timeframe.
Banking trojan derived from Zeus that spreads via phishing and targets Windows systems. It uses web injects, screenshots, keylogging, clipboard capture, and VNC-related capabilities to hijack sessions and steal credentials and other personal information. The campaigns described target financial institutions as well as cryptocurrency, social media, email, search, entertainment, ecommerce, tech, payroll, and adult sites.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.