Close Menu
CrafficCraffic
  • Home
  • News
    • Internet
    • Gaming
  • Tech
    • Hardware
    • Gaming Tech
    • Mobile Phones
    • Software
  • Science
    • Astronomy
    • Discoveries
    • Psychology
  • Entertainment
    • Anime
    • Reviews
    • Spotlight
    • WWE
Facebook X (Twitter) Instagram
CrafficCraffic
  • Home
  • News
    • Internet
    • Gaming
  • Tech
    • Hardware
    • Gaming Tech
    • Mobile Phones
    • Software
  • Science
    • Astronomy
    • Discoveries
    • Psychology
  • Entertainment
    • Anime
    • Reviews
    • Spotlight
    • WWE
Facebook X (Twitter) Instagram
CrafficCraffic
Home » Panda Stealer is After Your Cryptocurrency – Be Aware
Internet

Panda Stealer is After Your Cryptocurrency – Be Aware

Sudhanshu SharmaBy Sudhanshu SharmaMay 5, 2021Updated:May 6, 20212 Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Panda Stealer is After Your Cryptocurrencies – Be Aware
Share
Facebook Twitter LinkedIn Pinterest Email

Panda Stealer – Malware

A new type of malware, dubbed ‘Panda Stealer’ by researchers, is spreading through spam emails and malicious Discord links, and has its sights set firmly on your ever valuable cryptocurrency. According to Trend Micro, the phishing emails appear as business quote requests, with an XLSM file attached that’s loaded with malign macros. 

Excel File Malware

Panda Stealer appears as a harmless XLSSM file with macros that, when allowed, download a “loader” that runs the main “stealer” programme. Alternatively, an XLS file containing a formula that hides a Powershell command that accesses paste can be downloaded.

Currencies Effected

To get a new PowerShell instruction, use ee, a Pastebin substitute. Panda Stealer attempts to detect keys, addresses, and other data associated with cryptocurrency transactions and wallets containing funds such as Dash, Bytecoin, Litecoin, and Ethereum once it has been launched.

We are currently unsure whether the most recent cryptocurrency, Chia, is affected. It will also try to steal credentials from NordVPN, Telegram, Discord, and Steam, among other apps. It can take screenshots of the infected device and collect information from browsers such as cookies, passwords, and credit cards.

Panda Stealer Steals cryptocurrencies

Clone of Collector Stealer

Panda Stealer appears to be a clone of Collector Stealer, which has a cracked version available for download. Although no specific criminal group has been identified as the source of Panda Stealer, Trend Micro was able to detect an IP address used by the malware for command and control. It resulted in the suspension of a leased Shock Hosting virtual server after it was announced. 

2 Approaches the Malware Talks

Panda Stealer’s phishing emails seem to be requests for company quotes. The campaign has been connected to two approaches so far: the first uses attached. Victims must allow malicious macros in XLSM documents.

A loader then downloads and runs the main stealer if macros are allowed. 

A is connected to the second chain. An Excel formula in the XLS file hides a PowerShell order. This command tries to access a paste.ee URL in order to download a PowerShell script and then catch a fileless payload. 

Discord too Under Attack

However, VirusTotal discovered 264 related files in its database, calling home to 140 C&C servers and more than 10 download pages, including some from Discord, which could be used to spread malware between criminals.

Cryptocurrency Internet News Panda Stealer Phishing
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThis new gene-editing tool by Harvard scientists could rival CRISPR
Next Article This new YouTube feature will show you video titles, descriptions and captions in your native language
Sudhanshu Sharma

Related Posts

Gaming

God of War Ragnarok, Greatest of all time?

December 23, 2022
Gaming

How good will be Gran Turismo 7’s superhuman AI?

February 12, 2022
Entertainment

EXCLUSIVE! Dane DeHaan JOINS Christopher Nolan’s historical drama ‘Oppenheimer’

February 9, 2022
View 2 Comments

2 Comments

  1. Pingback: Scammers impersonating Elon Musk stole more than $2 Million in Cryptocurrency in the last 6 months - Craffic

  2. Pingback: 'Elon Musk Will Not Influence Cryptocurrency Forever' claims Ethereum Co-Founder Vitalik Buterin - Craffic

Leave A Reply Cancel Reply

At Craffic we ensure delivering quality content to our readers as they are giving us their precious time to engage with our content. And Craffic was a vision of a group of school friends and they've made it possible by learning the basics of strategies used in the media culture. ‎ ‎ ‎‎ ‎ ‎

Quick Access
  • About Us
  • Contact us
  • Terms of Use
  • Privacy Policy
Facebook X (Twitter) Instagram Pinterest
© 2025 Craffic. Designed by StackX Solutions.

Type above and press Enter to search. Press Esc to cancel.