{"id":2636,"date":"2021-05-07T20:51:05","date_gmt":"2021-05-08T01:51:05","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2636"},"modified":"2021-05-07T20:51:05","modified_gmt":"2021-05-08T01:51:05","slug":"pandastealer-the-new-threat-to-cryptocurrencies","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/","title":{"rendered":"PandaStealer, the new threat to cryptocurrencies"},"content":{"rendered":"\n<p>Trend Micro researchers have discovered a new variant of the cryptocurrency thief that uses a fileless approach in its global spam distribution campaign to evade detection. Dubbed PandaStealer, Trend Micro researchers said this week that the malware has been found targeting people in countries like the US, Australia, Japan and Germany.<\/p>\n\n\n\n<p>Spam emails pose as commercial quote requests to entice victims to click booby-trapped Excel files. Researchers found 264 files similar to Panda Stealer on VirusTotal, and some of them were shared by threat actors on Discord. That&#8217;s not surprising, given recent trends: Cisco&#8217;s Talos cybersecurity team recently found that threat actors have infiltrated workflow and collaboration tools like Slack and Discord to bypass security and deliver thieves. information, Remote Access Trojans (RAT) and other malware.<\/p>\n\n\n\n<p>Trend Micro identified two chains of infection. One uses an .XLSM attachment that contains macros that unload a loader, which is then downloaded and executed by the main thief. The second infection string method involves an attached .XLS file that contains an Excel formula that uses a PowerShell command to access paste.ee, an alternative to Pastebin, which accesses a second encrypted PowerShell command.<\/p>\n\n\n\n<p>PandaStealer has an infection chain that uses the same fileless distribution method as the &#8220;Regular&#8221; variant of the Phobos ransomware to carry out memory-based attacks, making it difficult to detect for security tools.<\/p>\n\n\n\n<p>Once downloaded, Panda Stealer will try to detect keys and addresses associated with cryptocurrency wallets containing funds, including Ethereum (ETH), Litecoin (LTC), Bytecoin (BCN), and Dash (DASH). Additionally, the malware can take screenshots, leak system data, and steal information, including browser cookies and credentials for NordVPN, Telegram, Discord, and Steam accounts.<\/p>\n\n\n\n<p>While the campaign has not been attributed to specific cyber attackers, Trend Micro says that an examination of the malware&#8217;s active command and control (C2) servers led the team to IP addresses and a virtual private server (VPS) rented from Shock Hosting. Since then, the server has been suspended.<\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/cryptocurrencies-security-is-a-growing-problem\/\">Cryptocurrencies security is a growing problem<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/\">Babuk Locker \u2013 The First Ransomware of 2021<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trend Micro researchers have discovered a new variant of the cryptocurrency thief that uses a fileless approach in its global spam distribution campaign to evade detection. Dubbed PandaStealer, Trend Micro researchers said this week that the malware has been found targeting people in countries like the US, Australia, Japan and Germany. Spam emails pose as [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2637,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2636","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PandaStealer, the new threat to cryptocurrencies - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Bad news ... A new threat on the web is spreading on the web, called PandaStealer, which we will see today and analyze what is known so far....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PandaStealer, the new threat to cryptocurrencies - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Bad news ... A new threat on the web is spreading on the web, called PandaStealer, which we will see today and analyze what is known so far....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-08T01:51:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/cripto-mone.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1300\" \/>\n\t<meta property=\"og:image:height\" content=\"831\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"PandaStealer, the new threat to cryptocurrencies\",\"datePublished\":\"2021-05-08T01:51:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/\"},\"wordCount\":345,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/cripto-mone.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/\",\"name\":\"PandaStealer, the new threat to cryptocurrencies - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/cripto-mone.jpg\",\"datePublished\":\"2021-05-08T01:51:05+00:00\",\"description\":\"Bad news ... A new threat on the web is spreading on the web, called PandaStealer, which we will see today and analyze what is known so far....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/cripto-mone.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/cripto-mone.jpg\",\"width\":1300,\"height\":831,\"caption\":\"Cyber crime and online theft concept. Vector of a virtual thief breaking into mobile internet account of a businessman stealing money from him\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/pandastealer-the-new-threat-to-cryptocurrencies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PandaStealer, the new threat to cryptocurrencies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PandaStealer, the new threat to cryptocurrencies - Truxgo Server Blog","description":"Bad news ... A new threat on the web is spreading on the web, called PandaStealer, which we will see today and analyze what is known so far....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/","og_locale":"es_MX","og_type":"article","og_title":"PandaStealer, the new threat to cryptocurrencies - Truxgo Server Blog","og_description":"Bad news ... A new threat on the web is spreading on the web, called PandaStealer, which we will see today and analyze what is known so far....","og_url":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-08T01:51:05+00:00","og_image":[{"width":1300,"height":831,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/cripto-mone.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"PandaStealer, the new threat to cryptocurrencies","datePublished":"2021-05-08T01:51:05+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/"},"wordCount":345,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/cripto-mone.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/","url":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/","name":"PandaStealer, the new threat to cryptocurrencies - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/cripto-mone.jpg","datePublished":"2021-05-08T01:51:05+00:00","description":"Bad news ... A new threat on the web is spreading on the web, called PandaStealer, which we will see today and analyze what is known so far....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/cripto-mone.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/cripto-mone.jpg","width":1300,"height":831,"caption":"Cyber crime and online theft concept. Vector of a virtual thief breaking into mobile internet account of a businessman stealing money from him"},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"PandaStealer, the new threat to cryptocurrencies"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2636"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2636\/revisions"}],"predecessor-version":[{"id":2651,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2636\/revisions\/2651"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2637"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}