New ‘Panda’ Malware Strain is After Your Cryptocoins

A new type of malware, dubbed ‘Panda Stealer’ by researchers, is spreading through spam emails and malicious Discord links, and has its sights set firmly on your ever valuable cryptocurrency. According to Trend Micro, the phishing emails appear as business quote requests, with an XLSM file attached that’s loaded with malign macros. 

Various cryptocurrencies lay on a table

(Image credit: Rūdolfs Klintsons from Pexels)

Panda Stealer seems to be a variant of Collector Stealer, a cracked build of which is freely available online. While there’s no evidence yet of a particular criminal group behind Panda Stealer, Trend Micro was able to identify an IP address being used by the malware for command and control. It led to a rented Shock Hosting virtual server, and having been reported, the server has been suspended. 

This may not be enough to quell the threat, however, as VirusTotal found 264 similar files in its database, calling home to 140 C&C servers and from more than 10 download sites, some of them from Discord, which may be being used to share the malware between criminals.

Ian Evenden
Freelance News Writer

Ian Evenden is a UK-based news writer for Tom’s Hardware US. He’ll write about anything, but stories about Raspberry Pi and DIY robots seem to find their way to him.

  • Exploding PSU
    Reading the title, I thought my Panda antivirus is turning against me heh
    Reply
  • Phaaze88
    It's just one thing after another...
    Dollars, Euros, Pounds, etc, get lost, stolen and used for ransom, and so does crypto...
    Reply