Executive Summary
Zeus Panda is a banking Trojan that steals credentials through keylogging and web form injection, persisting via registry run keys and scheduled tasks. It exfiltrates data over HTTPS to evade detection. The leak of its source code in 2011 has fueled widespread variant creation across Windows platforms.
Enhanced Description
Zeus Panda is a banking Trojan that exploits Windows operating systems ranging from XP to 10. The malware was originally released by the Zeus family and its source code leaked in 2011, providing threat actors with a template for developing new variants. Once installed, Zeus Panda targets web browsers to surreptitiously inject malicious forms or monitor keystrokes, thereby harvesting bank logins, credit card numbers, and other sensitive credentials. The Trojan also captures screenshots and can record clipboard contents, enabling it to recover authentication tokens that are often stored in memory by popular banking applications. Exfiltration occurs over encrypted HTTP/HTTPS channels directed at a compromised command‑and‑control (C2) server. Persistence is achieved through registry run keys and scheduled tasks so that the malware remains active across reboots. Variants may also employ dynamic DNS for C2 discovery, making them harder to track. Overall, Zeus Panda functions as a modular exploit kit: it gathers credentials via keylogging and form injection, maintains persistence, and delivers stolen data back to attackers. The leaked codebase has led to a proliferation of versions in the wild, many of which simply replicate older Zeus behaviors but may add new components such as malware‑as‑a‑service or botnet integration.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The data available gives a high-level view of standard Zeus‑family behaviors but lacks variant‑specific signatures or detailed attack vectors. Confidence is moderate: core capabilities are well documented, yet uncertainties remain regarding current operational C2 infrastructure and emerging sub‑variants.
Zeus Panda is a Trojan designed to steal banking information and other sensitive credentials for exfiltration. Zeus Panda’s original source code was leaked in 2011, allowing threat actors to use its source code as a basis for new malware variants. It is mainly used to target Windows operating systems ranging from Windows XP through Windows 10.(Citation: Talos Zeus Panda Nov 2017)(Citation: GDATA Zeus Panda June 2017)