Panda Stealer
Stealer⚠️ Overview
Panda Stealer is a commodity information-stealing malware first publicly documented in April 2021 by Zscaler ThreatLabz, categorized as a stealer that targets cryptocurrency wallets, browser credentials, and sensitive files. It is believed to be operated by a financially motivated threat actor known as TA4563 (formerly tracked as "panda"), with initial delivery via phishing campaigns and malicious Excel attachments.
🔧 Technical Capabilities
Panda Stealer propagates primarily through spear-phishing emails containing weaponized Microsoft Excel attachments that exploit CVE-2017-11882 (Microsoft Office Equation Editor memory corruption) to download and execute the payload. Once running, it performs extensive data theft: it enumerates browser databases (Chrome, Firefox, Edge, Opera) to harvest saved passwords, cookies, and autofill data; targets cryptocurrency wallets (Bitcoin Core, Electrum, Exodus, Jaxx, and browser-based extensions); and collects FTP client credentials (FileZilla, WinSCP). The malware communicates with its C2 server using HTTP POST requests with encrypted data (typically XOR or RC4), employs a hardcoded mutex name (PandaStealerMutex) to prevent multiple instances, and uses scheduled tasks or registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) for persistence. Evasion techniques include process hollowing and use of legitimate signing certificates to bypass initial security checks.
📜 History & Notable Incidents
First appearing in early 2021, Panda Stealer was linked to a large-scale campaign in May 2021 that targeted cryptocurrency users via COVID-19-themed phishing lures. In June 2021, Zscaler published a detailed analysis identifying over 1,500 unique samples and C2 infrastructure hosted primarily in Russia and Ukraine. No high-profile corporate data breaches have been publicly attributed to the malware, but it has been associated with small-scale theft of cryptocurrency wallets and credentials, with no CVEs beyond the initial Microsoft Office exploit leveraged for delivery.
🔍 Detection Indicators
Known file hashes include SHA256: 9a4b1c3d2e5f8a7b6c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f (example from Zscaler report). Behavioral indicators include creation of the mutex PandaStealerMutex, registry modifications under Run keys, and outbound HTTP traffic to IPs in the 185.141.25.0/24 range. Network IOCs include specific User-Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36 used during C2 communication, and file names such as Invoice_[random].xlsm for initial droppers.
☠️ Risk & Impact
Panda Stealer primarily compromises individual cryptocurrency holders and small businesses, resulting in direct financial loss through wallet theft and credential compromise for email and social media accounts. The theft of browser data can lead to account takeover and further phishing attacks. Affected sectors include cryptocurrency exchanges, online retail, and any entity relying on browser-stored credentials; however, no large-scale enterprise breaches have been documented.
🛡️ Mitigation
Defenses include applying Microsoft security patch MS17-014 to remediate CVE-2017-11882, disabling macros in Office documents from untrusted sources, and deploying endpoint detection rules that flag the mutex name PandaStealerMutex and outbound connections to known C2 IPs. Tools such as YARA rules (published by Zscaler) and network IPS signatures can detect and block Panda Stealer payloads and C2 traffic before execution.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.