Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ShadyPanda

Also known as: tracked as, Shell Crew, WebMasters, KungFu Kittens, PinkPanther

Description

ShadyPanda is an advanced threat actor that leveraged browser extensions as a vehicle for widespread compromise. Over a seven‑year campaign, attackers distributed malicious versions of popular productivity‑tool extensions via silent updates, injecting obfuscated JavaScript into web sessions and hijacking search queries on Chrome, Edge, and Firefox. The payload performs persistent reconnaissance by monitoring browsing behavior, collecting cookies, passwords, and other credentials, capturing screenshots, and harvesting meeting intelligence from over 28 video‑conferencing platforms. In addition to credential theft, the extensions use steganography to conceal code within PNG logos and deploy malicious .mobileconfig profiles or plist entries for silent installation of additional payloads. Data exfiltration occurs through a blend of WebSocket, HTTP, and custom TCP channels, reaching at least 17 different outbound domains. The campaign targets high‑value sectors—financial services, government, critical infrastructure, defense, healthcare, telecommunications, manufacturing, retail, think tanks—and spans US, India, Spain, and China. ShadyPanda’s operations illustrate a sophisticated supply‑chain strategy that combines extension updates, credential access, persistence via configuration tampering, anti‑analysis techniques, and multi‑stage exfiltration.

Goals & Targeting

Targeted Sectors

Financial services
Government
Critical infrastructure
Manufacturing
Telecommunications
Defense
Healthcare
Think tank
Retail

Targeted Countries / Regions

US
IN
ES
CN

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 20 hours ago

Executive Summary

ShadyPanda is a financially‑motivated threat actor that has conducted a 7‑year supply‑chain campaign infecting more than 4 million Chrome/Edge users through malicious browser extensions. The malware harvests credentials, captures screenshots and exfiltrates data via a range of covert channels while stealthily updating itself and manipulating system settings. Organizations must harden extension management and monitor for silent update activity to mitigate the threat.

Goals & Targeting

The actor’s primary objective is financial gain, achieved through large‑scale data theft of login credentials, payment information, corporate meeting intelligence, and potential espionage assets. By targeting sectors that handle sensitive personal or financial data, ShadyPanda maximizes the commercial value of stolen assets. The campaign’s persistence mechanisms—silent updates, preference file manipulation, and ad‑profile deployment—allow attackers to maintain long‑term access while evading detection.

Enhanced Description

Key Capabilities

  • Silent extension updates via hijacked update URLs
  • Injection of malicious JavaScript into browser sessions to redirect searches and alter browsing navigation
  • Browser activity monitoring, credential theft (cookies, passwords), screenshot capture
  • Installation of RAT/backdoors through malicious extensions
  • Manipulation of preference files for silent installation without user consent
  • Steganographic embedding of malware code within PNG logos/screenshots
  • Exfiltration of data to untrusted domains via browser processes or command‑and‑control channels
  • Use of malicious .mobileconfig profiles or plist entries for ad delivery and persistence
  • Triggering abnormal child process activity after extension installation

MITRE ATT&CK Tactics

Execution
Persistence
Credential Access
Collection
Command and Control
Defense Evasion
Exfiltration

ATT&CK Techniques

T1059
T1059.003
T1059.007
T1071.001
T1087
T1105
T1113
T1218
T1021
T1047
T1027
T1555.003
T1557
T1546
T1505
T1564
T1566.001
T1176
T1176.001
T1176.002

Software / Tooling

ShadyPanda browser extension
GhostPoster extension
Zoom Stealer extension
Bundlore
Grandoreiro
TRANSLATEXT
Rilide

Campaigns & Victims

ShadyPanda’s operations have unfolded on a consistent, long‑term basis, with periodic bursts of new malicious extensions and updates over seven years. The actor predominantly leverages supply‑chain tactics—primarily through browser update mechanisms—to infect millions of users. Infected victims include employees in finance, government, defense, healthcare, and critical infrastructure, with a geographic focus on the United States, India, Spain, and China. Notable campaign characteristics include silent extension updates that evade user notice, exfiltration to dozens of untrusted domains, the use of steganographic techniques within image files, and the deployment of malicious configuration profiles to establish persistence and broaden reach.

IOC Patterns

  • Malicious browser extensions with high‑risk permission patterns
  • Hidden JavaScript code embedded in image logos of extensions
  • Suspicious update URLs pointing to adversary‑controlled servers
  • Manipulated preference or Secure Preferences files for silent installation
  • Planted .mobileconfig files used for silent installation
  • Abnormal child process activity after extension install

Recommended Actions

  • Implement an extension inventory and risk assessment solution (e.g., Zscaler SSPM) to detect non‑approved extensions.
  • Enforce whitelisting for all browser extensions and review high‑risk permission requests before approval.
  • Monitor for anomalous silent update traffic from extension manifests and block updates that redirect to unfamiliar domains.
  • Restrict modification of browser preference files or secure preferences to prevent stealthy installs.
  • Disable automatic installation of unknown .mobileconfig profiles or plist entries at the OS level.
  • Educate users on phishing and social‑engineering tactics used to lure them into installing malicious extensions.
  • Configure group policies to allow only trusted, signed extensions from vetted vendors.
  • Shut down browser sessions when idle and enforce multi‑factor authentication to mitigate credential theft.
  • Block outbound traffic to known exfiltration endpoints identified in IOC lists.

Suggested Tags

browser-extensions
malicious-extensions
silent-updates
credential-theft
rat-backdoor
chrome-attack
edge-extension-exploit
firefox-injection
zscaler-sspm
darkspectre
credential-stealing
data-exfiltration
adware

Confidence Assessment

The available data provides high confidence in the scope of user infection, malicious behavior patterns, and primary motivation, based on publicly reported numbers and technical analysis. Attribution to a specific nation‑state or criminal organization remains uncertain; thus confidence is moderate regarding organizational attribution and adversary intent beyond financial motive. Data gaps include definitive attribution evidence, detailed weaponization chain specifics, and temporal activity of the earliest campaign phases.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 5 Domain 4 Filename 11

References

  1. attack.mitre.org — Cited by web research for: Shell Crew
  2. attack.mitre.org — Cited by web research for: T1176.002
  3. www.rescana.com — Cited by web research for: T1059.007
  4. www.malwarebytes.com — Cited by web research for: Malwarebytes
  5. www.trendmicro.com — Cited by web research for: PlugX
  6. www.zscaler.com — Cited by web research for: Global
  7. www.koi.ai — Cited by web research for: trovi.com
  8. https://www.rescana.com/post/shadypanda-browser-extension-attack-4-3-million-chrome-and-edge-users-compromised-in-multi-year-supply-chain-campaign — Cited by AI analysis.

Intel Summary

22

Techniques

45

Tools

0

Campaigns

39

IOCs

0

Observed Data

10

Tactics

Tags

APT
Critical Infrastructure
Data Exfiltration
Espionage
Surveillance
Browser Extensions
browser-extensions
malicious-extensions
silent-updates
credential-theft
rat-backdoor
chrome-attack
edge-extension-exploit
firefox-injection
zscaler-sspm
darkspectre
credential-stealing
data-exfiltration
adware

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
India (IN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.