Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Zeus Panda

Zeus Panda

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

Zeus Panda is a banking Trojan that steals credentials through keylogging and web form injection, persisting via registry run keys and scheduled tasks. It exfiltrates data over HTTPS to evade detection. The leak of its source code in 2011 has fueled widespread variant creation across Windows platforms.

Enhanced Description

Zeus Panda is a banking Trojan that exploits Windows operating systems ranging from XP to 10. The malware was originally released by the Zeus family and its source code leaked in 2011, providing threat actors with a template for developing new variants. Once installed, Zeus Panda targets web browsers to surreptitiously inject malicious forms or monitor keystrokes, thereby harvesting bank logins, credit card numbers, and other sensitive credentials. The Trojan also captures screenshots and can record clipboard contents, enabling it to recover authentication tokens that are often stored in memory by popular banking applications. Exfiltration occurs over encrypted HTTP/HTTPS channels directed at a compromised command‑and‑control (C2) server. Persistence is achieved through registry run keys and scheduled tasks so that the malware remains active across reboots. Variants may also employ dynamic DNS for C2 discovery, making them harder to track. Overall, Zeus Panda functions as a modular exploit kit: it gathers credentials via keylogging and form injection, maintains persistence, and delivers stolen data back to attackers. The leaked codebase has led to a proliferation of versions in the wild, many of which simply replicate older Zeus behaviors but may add new components such as malware‑as‑a‑service or botnet integration.

Key Capabilities

  • Steals bank login credentials by injecting malicious forms into browsers
  • Keylogging to capture user input, including passwords and sensitive data
  • Screenshots and clipboard monitoring for additional credential leakage
  • PERSISTENCE via registry run keys and scheduled tasks
  • Exfiltration of stolen data over encrypted HTTPS channels
  • Modular architecture allowing attackers to add or reconfigure modules with relative ease

ATT&CK Techniques

T1055
T1003
T1041
T1071.001

Recommended Actions

  • Deploy endpoint detection & response (EDR) solutions capable of identifying Zeus‑family indicators such as known process names and YARA signatures
  • Monitor outbound connections for suspicious HTTPS activity to unfamiliar domains or IPs, filtering per threat‑intel feeds
  • Implement application whitelisting to block execution of unsigned binaries on Windows platforms
  • Patch legacy features (e.g., outdated IE and Flash) that are often used for web injection
  • Use network segmentation and strict firewall rules to limit lateral movement
  • Conduct user security awareness training focused on phishing and credential theft
  • Apply the latest Windows OS patches, including disabling older authentication protocols prone to exploitation

Suggested Tags

Trojan
Banking Trojan
Credential Theft
Web Injection
Keylogger
Data Exfiltration
Windows Malware
Malware Family

Confidence Assessment

The data available gives a high-level view of standard Zeus‑family behaviors but lacks variant‑specific signatures or detailed attack vectors. Confidence is moderate: core capabilities are well documented, yet uncertainties remain regarding current operational C2 infrastructure and emerging sub‑variants.

Description

Zeus Panda is a Trojan designed to steal banking information and other sensitive credentials for exfiltration. Zeus Panda’s original source code was leaked in 2011, allowing threat actors to use its source code as a basis for new malware variants. It is mainly used to target Windows operating systems ranging from Windows XP through Windows 10.(Citation: Talos Zeus Panda Nov 2017)(Citation: GDATA Zeus Panda June 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.