Saturday, August 29, 2026

Dangerous PANDA Banking Malware Spreads Through Phishing Attacks Targets Banks, Cryptocurrency Sites and Social Media

The PANDA Malware first identified in the year 2016 by Fox IT, the malware primarily focused on banking sectors. With the last February, the campaign was heavily focused on cryptocurrency sites and the three active campaigns currently focusing on social media(Twitter and Facebook).

According to F5 researchers, the four active campaigns that appear between February to May of 2018 uses the same botnet but having different targets and C&C servers.

But still, the panda malware still focussing financial sectors, due to the recent hype with cryptocurrency it expands it’s targeted to online cryptocurrency exchanges, also it focuses Social media, search, email, and adult sites.

The malware campaigns primarily focussed on the Japanese financial organizations and all the campaign in the month of May targeted social media, search, email, e-commerce, and tech providers.

PANDA Malware

Researchers said, “we analyzed February campaign marked as botnet “onore2” targets Italian Financial Services and Cryptocurrency Sites Equally. The majority of targets are financial services 51% and cryptocurrency targets 49% worldwide.

PANDA Malware

The last campaign marked Botnet “2.6.8” Targets US Financials and the campaign hits 8 industries 76% of which were US financial organizations, 8% Canadian financial services, 6% cryptocurrency sites, 4% social media, 3% search and email and 1% payroll sites.

Also Read Most Important Security Tools and Resources For Security Researcher, Malware Analyst, Reverse Engineer

The May Campaign Botnet “2.6.8” also Targets Japanese Financials, 52% Japanese financial services, 14% search and email providers, 9% social media, 10% adult sites, 5% tech provider, 5% eCommerce, 5% Entertainment.

With the third parallel campaign Botnet “Cosmos3” targets financial institutions in Latin America. The campaign primarily focuses on financial institutions in Argentina, Columbia, and Ecuador followed by the social media, search and tech provider.

F5 concludes that “Panda’s expansion beyond traditional banking targets, the act of simultaneous campaigns targeting several regions around the world and industries indicates these are highly active threat actors. we highly recommend all businesses maintain up-to-date patches on endpoints and ensure AV controls are continuously updated.”

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Compromise TanStack Query npm Package to Steal Developer Credentials

A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen,...

Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal

A critical vulnerability in Gogs, the self-hosted Git service,...

Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel

A newly documented TerminalFix campaign is using fake Cloudflare...

Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data

A Chinese-speaking threat actor tracked as TA4922 is deploying...

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value...

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of...

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism...

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in...

Related Articles

Recent News