ShadyPanda is a likely China-linked threat actor associated with long-running malicious browser-extension operations targeting Google Chrome and Microsoft Edge users. The group is known for abusing trusted browser marketplaces and extension auto-update mechanisms: it operated seemingly legitimate extensions for extended periods to accumulate installs, reviews, and trust signals, then pushed malicious updates that converted those extensions into spyware and browser backdoors. Reporting links the actor to campaigns affecting more than 4.3 million browser installations over roughly seven years. ShadyPanda’s activity evolved over time. Early operations used large numbers of extensions for affiliate fraud and user profiling. Later campaigns escalated to active browser manipulation, including search redirection, traffic manipulation, and covert surveillance. More advanced phases introduced remote retrieval and execution of arbitrary JavaScript within the browser context, effectively giving the actor persistent post-compromise control over infected browsers. Observed collection included browsing history, search queries, mouse and click telemetry, browser fingerprints, cookies, and other session data, creating both espionage and session-hijacking risk. The actor also used obfuscation, delayed activation, and analyst-evasion behavior such as reverting to benign behavior during inspection. The actor’s operations have been described as a browser supply-chain compromise because they relied on the trust model of extension ecosystems rather than phishing or overt malware delivery. This made the campaigns particularly dangerous in enterprise environments, where compromised browsers could expose SaaS sessions, cloud-console access, developer credentials, API keys, and internal web applications. Named extensions repeatedly associated with the campaign include Clean Master, Infinity V+, and WeTab. ShadyPanda has also been associated in reporting with DarkSpectre and GhostPoster as related or overlapping browser-extension operations. The dominant pattern across reporting is long-term surveillance and covert access through weaponized extensions, consistent with espionage-oriented tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as core infrastructure associated with DarkSpectre in the disputed Koi report.
Referenced as a campaign previously connected to DarkSpectre.
Named as a related extension campaign linked by Koi Security to DarkSpectre.
ShadyPanda is a China-linked group running long-term malicious browser extension campaigns for surveillance and remote control.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.