LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0330: Zeus Panda

Zeus Panda is a Trojan designed to steal banking information and other sensitive credentials for exfiltration. Zeus Panda’s original source code was leaked in 2011, allowing threat actors to use its source code as a basis for new malware variants. It is mainly used to target Windows operating systems ranging from Windows XP through Windows 10.[1][2]

EnterpriseS0330MalwareObject v1.4Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Zeus Panda matters because ATT&CK describes it as Windows banking Trojan malware built to steal banking information and other sensitive credentials for exfiltration. Its listed behaviors span credential collection, discovery, persistence through Registry Run Keys or Startup Folder, web-protocol command and control, tool/file transfer, obfuscation, and cleanup. For leaders, the practical issue is not just one malware name; it is whether Windows endpoint, identity, and SOC controls can detect and contain credential theft malware that blends discovery, stealth, and persistence behaviors.

Executive priority

Prioritize Zeus Panda as a validation case for Windows credential-theft resilience: endpoint visibility, registry-change monitoring, PowerShell/cmd governance, web egress review, and incident response playbooks for stolen credentials. Because ATT&CK provides no official detection text for this software, executives should ask whether coverage is proven through local telemetry and tests mapped to the related techniques, not assumed from malware signatures alone.

Technical view

ATT&CK lists Zeus Panda on Windows and relates it to techniques including Query Registry, Modify Registry, Registry Run Keys / Startup Folder, Command and Scripting Interpreter, PowerShell, Windows Command Shell, Portable Executable Injection, Keylogging, Credential API Hooking, Process Discovery, System Information Discovery, Security Software Discovery, File and Directory Discovery, System Time Discovery, System Language Discovery, Clipboard Data, Screen Capture, Web Protocols, Ingress Tool Transfer, File Deletion, obfuscated commands, encrypted/encoded files, and deobfuscation. SOC and IR teams should validate detection across the behavior chain: initial execution via shell or PowerShell, discovery commands, suspicious registry reads/writes and autoruns, process injection indicators, credential and user-data collection signals, outbound HTTP/S-like C2 patterns, downloaded files, and post-activity deletion.

Likely telemetry

  • Windows process creation and command-line history for cmd.exe, PowerShell, and child processes
  • PowerShell execution logs and script/block-level evidence where available
  • Windows Registry read/write events, especially Run Keys and startup-related locations
  • Endpoint file creation, modification, deletion, and encoded/encrypted artifact indicators
  • Process access, memory allocation, thread creation, or other endpoint signals consistent with PE injection

Detection direction

  • Do not rely only on Zeus Panda name-based or hash-based detections; the source code leak noted by ATT&CK means variants may exist, so behavior-level analytics are important.
  • Tune detections around combinations of behaviors: shell or PowerShell execution followed by discovery, registry modification, persistence creation, file transfer, and web egress.
  • Validate Registry Run Key and startup-folder monitoring for both user-context and elevated contexts; triage should distinguish legitimate software updaters from unusual persistence paths or newly introduced binaries.
  • Correlate credential-access behaviors such as keylogging, API hooking, clipboard access, and screen capture with suspicious process lineage and network activity to reduce false positives.
  • Review blind spots where command obfuscation, encoded files, or deobfuscation may weaken simple string or command-line matching.

Mitigation priorities

  • Harden Windows endpoints against credential theft by prioritizing least privilege, application control where feasible, and rapid isolation procedures for suspected infected hosts.
  • Restrict and monitor PowerShell and Windows command shell usage according to administrative need; preserve sufficient logging for investigation.
  • Monitor and control Registry persistence locations and startup folders; investigate unauthorized changes promptly.
  • Strengthen egress controls and proxy/DNS visibility for web-protocol command-and-control and tool-transfer patterns.
  • Ensure endpoint protection and EDR policies are configured to capture process injection, suspicious file activity, and credential-access behaviors, not just known malware signatures.
Additional notes and limits

This take is based on the supplied ATT&CK S0330 Zeus Panda object, its official description, external references from Talos and G DATA, and listed technique relationships. The strongest business relevance is credential theft from Windows systems and the need to validate behavior-based coverage across discovery, stealth, persistence, collection, command and control, and file transfer behaviors.

ATT&CK does not provide official detection text, aliases, labels, or explicit tactics for the Zeus Panda malware object in the supplied fields. Relationship descriptions are partially truncated in the source provided. Local environment evidence is required to determine actual exposure, detection coverage, affected Windows versions in use, and whether any observed activity is Zeus Panda versus another malware family using similar techniques.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Zeus Panda

Zeus Panda is a Trojan designed to steal banking information and other sensitive credentials for exfiltration. Zeus Panda’s original source code was leaked in 2011, allowing threat actors to use its source code as a basis for new malware variants. It is mainly used to target Windows operating systems ranging from Windows XP through Windows 10.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

23 rows
DomainIDNameRelationship / procedure
EnterpriseT1056.004Credential API HookingSub-technique

Zeus Panda hooks processes by leveraging its own IAT hooked functions.[2]

EnterpriseT1059.001PowerShellSub-technique

Zeus Panda uses PowerShell to download and execute the payload.[1]

EnterpriseT1518.001Security Software DiscoverySub-technique

Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment.[1][2]

EnterpriseT1057Process Discovery

Zeus Panda checks for running processes on the victim’s machine.[2]

EnterpriseT1113Screen Capture

Zeus Panda can take screenshots of the victim’s machine.[2]

EnterpriseT1105Ingress Tool Transfer

Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine.[2]

EnterpriseT1059Command and Scripting Interpreter

Zeus Panda can launch remote scripts on the victim’s machine.[2]

EnterpriseT1124System Time Discovery

Zeus Panda collects the current system time (UTC) and sends it back to the C2 server.[2]

EnterpriseT1614.001System Language DiscoverySub-technique

Zeus Panda queries the system's keyboard mapping to determine the language used on the system. It will terminate execution if it detects LANG_RUSSIAN, LANG_BELARUSIAN, LANG_KAZAK, or LANG_UKRAINIAN.[1]

EnterpriseT1112Modify Registry

Zeus Panda modifies several Registry keys under HKCU\Software\Microsoft\Internet Explorer\ PhishingFilter\ to disable phishing filters.[2]

EnterpriseT1071.001Web ProtocolsSub-technique

Zeus Panda uses HTTP for C2 communications.[1]

EnterpriseT1070.004File DeletionSub-technique

Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track.[2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4.[1][2]

EnterpriseT1027.010Command ObfuscationSub-technique

Zeus Panda obfuscates the macro commands in its initial payload.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

Zeus Panda can launch an interface where it can execute several commands on the victim’s PC.[2]

EnterpriseT1115Clipboard Data

Zeus Panda can hook GetClipboardData function to watch for clipboard pastes to collect.[2]

EnterpriseT1012Query Registry

Zeus Panda checks for the existence of a Registry key and if it contains certain values.[2]

EnterpriseT1055.002Portable Executable InjectionSub-technique

Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process.[2]

EnterpriseT1082System Information Discovery

Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system.[1][2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Zeus Panda adds persistence by creating Registry Run keys.[1][2]

EnterpriseT1056.001KeyloggingSub-technique

Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN.[2]

EnterpriseT1140Deobfuscate/Decode Files or Information

Zeus Panda decrypts strings in the code during the execution process.[1]

EnterpriseT1083File and Directory Discovery

Zeus Panda searches for specific directories on the victim’s machine.[2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.4
Created
Modified
Raw hash
af83cc8fb717d5d4...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.4Current bundleaf83cc8fb717…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  2. [2]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  3. [3]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  4. [4]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  5. [5]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  6. [6]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  7. [7]
    Zeus Panda

    (Citation: Talos Zeus Panda Nov 2017)(Citation: GDATA Zeus Panda June 2017)

  8. [8]
    Zeus Panda

    (Citation: Talos Zeus Panda Nov 2017)(Citation: GDATA Zeus Panda June 2017)

  9. [9]
    Zeus Panda

    (Citation: Talos Zeus Panda Nov 2017)(Citation: GDATA Zeus Panda June 2017)

  10. [10]
    mitre-attackS0330
    Open source URL
  11. [11]
    mitre-attackS0330
    Open source URL
  12. [12]
    mitre-attackS0330
    Open source URL
  13. [13]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  14. [14]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  15. [15]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  16. [16]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  17. [17]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  18. [18]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  19. [19]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  20. [20]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  21. [21]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  22. [22]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  23. [23]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  24. [24]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  25. [25]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  26. [26]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  27. [27]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  28. [28]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  29. [29]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  30. [30]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  31. [31]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  32. [32]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  33. [33]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  34. [34]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  35. [35]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  36. [36]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  37. [37]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  38. [38]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  39. [39]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  40. [40]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  41. [41]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  42. [42]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  43. [43]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  44. [44]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  45. [45]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  46. [46]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  47. [47]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  48. [48]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  49. [49]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  50. [50]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  51. [51]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  52. [52]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  53. [53]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  54. [54]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  55. [55]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  56. [56]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  57. [57]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  58. [58]
    Talos Zeus Panda Nov 2017

    Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

    Open source URL
  59. [59]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.