Share this article

'Panda' Malware Targets Crypto Wallets and Users' Discord, Telegram Accounts

The main "new" aspect here is the target of the data theft.

Updated Sep 14, 2021, 12:53 p.m. Published May 10, 2021, 10:03 p.m.
billow926-DHyIWBm8NGc-unsplash

A new ransomware attack is going after cryptocurrency wallets, along with account credentials from other applications such as NordVPN, Telegram, Discord and Steam.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

Dubbed “Panda,” the new information-stealing malware (also called infostealer for short) was discovered by Trend Micro, a cybersecurity software company.

“Crypto wallets are now as big of a target for online theft as banking accounts are,” said the Trend Micro researchers who discovered the attack. “With more people getting into cryptocurrencies and the values of said cryptocurrencies still increasing, this will only become a greater threat moving forward.”

They also said there is more risk here because unlike with a bank robbery or credit card theft, there may not be a central authority that can undo malicious transactions. Once you lose your money and the transaction goes on the blockchain, it's likely gone forever.

The malware attack

At a high level, according to the researchers, the attack begins with spam messages that contain a malicious attachment. The attachment uses PowerShell scripts, a task automation and configuration management coding language Microsoft, to download the actual Panda Stealer malware (in encoded form), which is then loaded without files onto the affected system.

“None of this is particularly novel in and of itself – malicious Office documents are well known, so is fileless loading,” the researchers said. “The main 'new' aspect here is the target of the data theft.”

Beyond just targeting cryptocurrency wallets with malware, attackers are now setting their sights on applications like Discord and Telegram – popular communications platforms for cryptocurrency communities.

Read more: This Elusive Malware Has Been Targeting Crypto Wallets for a Year

The attack campaign, which was active in April, uses spam emails and the same rare fileless distribution method as a separate recent attack. Morphisec, another cybersecurity firm, discovered a Phobos ransomware campaign in early April that uses an identical fileless distribution method to Panda, making it more difficult for security tools to spot.

"The fileless distribution used in this case means there is no signature for antivirus software to detect the threat, and it can bypass detection,” said Michael Gorelik, chief technology officer and head of threat intelligence at Morphisec. “Therefore, it's dangerous for both consumers' wallets and even enterprises, with more lines of security set up."

Follow best security practices

The Trend Micro researchers said following long-standing security practices still applies here. Not opening up attachments sent via email, making sure you don’t click on unknown links and keeping software upgraded still are basic security measures people can take to avoid malware and other security breaches.

Specific to cryptocurrencies, they said the best advice is to secure your cryptocurrency wallets. They weren’t able to give specific recommendations given the wide array of wallets on the market, but recommended using strong, unique passwords.

“If the wallet you're using offers multifactor authentication (and many do – if anything, they may support multiple methods), use them,” the researchers said. “For investors who are more interested in holding cryptocurrencies for the long term instead of actively trading them, the use of hardware-based/offline wallets may well be safer, if less convenient to add to or sell from.”

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Solana’s Drift Launches v3, With 10x Faster Trades

Drift (b52_Tresa/Pixabay)

With v3, the team says that about 85% of market orders will fill in under half a second, and liquidity will deepen enough to bring slippage on larger trades down to around 0.02%.

What to know:

  • Drift, one of the largest perpetuals trading platforms on Solana, has launched Drift v3, a major upgrade meant to make on-chain trading feel as fast and smooth as using a centralized exchange.
  • The new version will deliver 10-times faster trade execution thanks to a rebuilt backend, marking the largest performance jump the project has made so far.