Skip to content

Banking trojan

PandaBanker

aka ZeusPanda

According to Arbor, Forcepoint and Proofpoint, Panda is a variant of the well-known Zeus banking trojan(*).

PandaBanker, also known as ZeusPanda, is a Windows banking trojan.

Background

Arbor, Forcepoint and Proofpoint report that Panda is a spin-off of the well-known Zeus banking trojan(*), first spotted by Fox IT in February 2016.

The trojan leans on the notorious ATS (Automatic Transfer System/Scripts) to automate actions within online banking portals.

Its base configuration (c2, crypto material, botnet name, version) is baked into the binary. From there it pulls a dynamic config from the c2 that explains how to fetch the webinjects and extra modules like vnc, backsocks and grabber.

Panda includes some DGA functionality, but according to Arbor a bug keeps it from actually being used.


Source: Malpedia (Fraunhofer FKIE).