Malware.View on attack.mitre.org
Zeus Panda is a Trojan designed to steal banking information and other sensitive credentials for exfiltration. Zeus Panda’s original source code was leaked in 2011, allowing threat actors to use its source code as a basis for new malware variants. It is mainly used to target Windows operating systems ranging from Windows XP through Windows 10.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
Zeus Panda checks for the existence of a Registry key and if it contains certain values. |
| T1027.010 Command Obfuscation |
Zeus Panda obfuscates the macro commands in its initial payload. |
| T1027.013 Encrypted/Encoded File |
Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4. |
| T1055.002 Portable Executable Injection |
Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process. |
| T1056.001 Keylogging |
Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN. |
| T1056.004 Credential API Hooking |
Zeus Panda hooks processes by leveraging its own IAT hooked functions. |
| T1057 Process Discovery |
Zeus Panda checks for running processes on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
Zeus Panda can launch remote scripts on the victim’s machine. |
| T1059.001 PowerShell |
Zeus Panda uses PowerShell to download and execute the payload. |
| T1059.003 Windows Command Shell |
Zeus Panda can launch an interface where it can execute several commands on the victim’s PC. |
| T1070.004 File Deletion |
Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track. |
| T1071.001 Web Protocols |
Zeus Panda uses HTTP for C2 communications. |
| T1082 System Information Discovery |
Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system. |
| T1083 File and Directory Discovery |
Zeus Panda searches for specific directories on the victim’s machine. |
| T1105 Ingress Tool Transfer |
Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.