ShadyPanda is a long-running malicious browser-extension surveillance operation associated with a China-linked threat actor cluster referred to as DarkSpectre. The campaign weaponized trusted-looking browser extensions across major extension ecosystems, including Chrome, Microsoft Edge, and Firefox, and reportedly operated for years at large scale. It relied on building user trust through benign or low-profile functionality and then enabling malicious behavior through server-side configuration and extension update mechanisms, allowing operators to change capabilities without necessarily publishing conspicuous new versions.
ShadyPanda functioned as spyware focused on large-scale browser-based surveillance and remote control. Reported behaviors include collection of browsing-related data and other user information from infected browsers, with the broader operator tradecraft centered on persistent access through extensions that could remain installed for long periods. The campaign also reportedly maintained numerous dormant or sleeper extensions that could later be weaponized, indicating an emphasis on persistence, operational patience, and scalable post-compromise control.
The activity has been described as part of a broader ecosystem of malicious extension campaigns tied to the same operator, alongside GhostPoster and Zoom Stealer. Across these related operations, the actor demonstrated techniques such as delayed activation, configuration-driven tasking, real-time data collection, and abuse of trusted extension marketplaces. ShadyPanda stands out as a flagship campaign notable for its duration, scale, and use of ostensibly legitimate browser add-ons as a covert espionage platform affecting millions of users globally.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparable malicious browser-extension campaign used to gather data at scale.
Malicious browser extension campaign enabling surveillance and remote control, distributed via Chrome and Edge extension marketplaces.
Named campaign/tool referenced in malicious browser-extension activity; specific functionality is not detailed beyond extension-based exfiltration and impersonation tactics.
Spyware referenced as compromising millions of users by abusing trusted browser extensions and their auto-update mechanism; tags also indicate backdoor functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.