This panda hungers for your Steam and Discord logins

Panda Stealer wants your data
(Image credit: Pixabay - Katchi)

Here come the hackers again, poised to relieve you of your cryptocurrency and break into your Steam and Discord accounts. And in the same fell swoop, besmirching the name of the most pure and non-malign bear on the planet: the panda. 

'Panda Stealer' is being distributed through phishing emails and Discord links, and is hell-bent on picking out any cryptocurrency-related data on your machine. As TrendMicro outlines, your Ethereum, Dash, Bytecoin and Litecoin keys and addresses are all at risk, though there's no mention of other currencies being affected (via Tom's Hardware). 

The malware—which utilises a fileless distribution method to remain undetected—also has a taste for NordVPN, Telegram, Discord, and Steam details, and is able to take screenshots, pilfer passwords and card credentials, as well as raid both the virtual and proverbial cookie jar.

Business quote requests is usually how the software masquerades in your inbox. Once you click through, the waltz begins with an XLSM or XLS file download. Once in, the malware worms its way through your system with a formula veiling a PowerShell command, accesses paste.ee and gives itself permission to download yet more PowerShell commands to retrieve your super-secret info—all in the blink of an eye.

Attempts have been made to trace the virus back to its IP of origin, and although it only threw up a rented Shock Hosting virtual server, it has been reported and the server suspended. But it probably won't help much.

The best bet is that Panda Stealer is a variant of Collector Stealer, for which cracked downloads are freely available across the net. When consulted, VirusTotal showed 264 similar malwares, scattered across a boatload of servers and download sites. Discord is expected as a likely method for its transferal between baddies who want to steal your cryptocurrency riches and Steam wallet funds.

So, as always, be hyper-aware of what you're clicking. And make sure you grab one of the best antivirus programs, just to be sure. 

Katie Wickens
Hardware Writer

Screw sports, Katie would rather watch Intel, AMD and Nvidia go at it. Having been obsessed with computers and graphics for three long decades, she took Game Art and Design up to Masters level at uni, and has been rambling about games, tech and science—rather sarcastically—for four years since. She can be found admiring technological advancements, scrambling for scintillating Raspberry Pi projects, preaching cybersecurity awareness, sighing over semiconductors, and gawping at the latest GPU upgrades. Right now she's waiting patiently for her chance to upload her consciousness into the cloud.

Read more
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
An image of a fake Bitcoin with a laptop in the background displaying financial data
North Korean hackers are said to have stolen $1,300,000,000 in crypto in 2024, an estimated 61% of the total funds swiped this year
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
 In this photo illustration a novelty Bitcoin token is photographed on a US Dollar bank note, on January 4, 2025 in Bath, England. The Cryptocurrency market has recently received a significant boost by the election of Donald Trump with hopes of the start of a policy framework that could see Bitcoin as a strategic asset
Man charged with $65,000,000 worth of cryptocurrency heists was reportedly discovered through chatting on Discord with a company they allegedly stole from
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
A catgirl with long white hair and ears
At least it's not NFTs this time: The new Wizardry RPG is a gacha game
Staring eyes in a face covered in oil
Death Stranding 2's PS5 release date is in June, let's hope it doesn't take 8 months to hit PC this time
An evil-looking demon with red eyes and horns
You can theoretically beat Doom: The Dark Ages without using a gun, but 'You'd have a hard time, that's for sure,' says the game's director
Official Doom Guy art superimposed over Vault 666 Fallout-themed background.
Fallout-themed Doom mod Vault 666 has multiple endings, an OP Dogmeat companion, and a Ron Perlman-impersonating narrator so good, I was worried it was AI-generated at first
The Doomslayer in armor
Doom: The Dark Ages won't end with the Slayer in a coffin waiting for the start of Doom 2016: 'That would mean that we couldn't tell any more medieval stories'
Path of Exile 2 showing the Warbringer ascendancy class bludgeoning his way through a pack of hyenas
Path of Exile 2 speedrunner dominates official race with the game's 'worst' class