Also known as: tracked as, Shell Crew, WebMasters, KungFu Kittens, PinkPanther
ShadyPanda is an advanced threat actor that leveraged browser extensions as a vehicle for widespread compromise. Over a seven‑year campaign, attackers distributed malicious versions of popular productivity‑tool extensions via silent updates, injecting obfuscated JavaScript into web sessions and hijacking search queries on Chrome, Edge, and Firefox. The payload performs persistent reconnaissance by monitoring browsing behavior, collecting cookies, passwords, and other credentials, capturing screenshots, and harvesting meeting intelligence from over 28 video‑conferencing platforms. In addition to credential theft, the extensions use steganography to conceal code within PNG logos and deploy malicious .mobileconfig profiles or plist entries for silent installation of additional payloads. Data exfiltration occurs through a blend of WebSocket, HTTP, and custom TCP channels, reaching at least 17 different outbound domains. The campaign targets high‑value sectors—financial services, government, critical infrastructure, defense, healthcare, telecommunications, manufacturing, retail, think tanks—and spans US, India, Spain, and China. ShadyPanda’s operations illustrate a sophisticated supply‑chain strategy that combines extension updates, credential access, persistence via configuration tampering, anti‑analysis techniques, and multi‑stage exfiltration.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ShadyPanda is a financially‑motivated threat actor that has conducted a 7‑year supply‑chain campaign infecting more than 4 million Chrome/Edge users through malicious browser extensions. The malware harvests credentials, captures screenshots and exfiltrates data via a range of covert channels while stealthily updating itself and manipulating system settings. Organizations must harden extension management and monitor for silent update activity to mitigate the threat.
Goals & Targeting
The actor’s primary objective is financial gain, achieved through large‑scale data theft of login credentials, payment information, corporate meeting intelligence, and potential espionage assets. By targeting sectors that handle sensitive personal or financial data, ShadyPanda maximizes the commercial value of stolen assets. The campaign’s persistence mechanisms—silent updates, preference file manipulation, and ad‑profile deployment—allow attackers to maintain long‑term access while evading detection.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ShadyPanda’s operations have unfolded on a consistent, long‑term basis, with periodic bursts of new malicious extensions and updates over seven years. The actor predominantly leverages supply‑chain tactics—primarily through browser update mechanisms—to infect millions of users. Infected victims include employees in finance, government, defense, healthcare, and critical infrastructure, with a geographic focus on the United States, India, Spain, and China. Notable campaign characteristics include silent extension updates that evade user notice, exfiltration to dozens of untrusted domains, the use of steganographic techniques within image files, and the deployment of malicious configuration profiles to establish persistence and broaden reach.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides high confidence in the scope of user infection, malicious behavior patterns, and primary motivation, based on publicly reported numbers and technical analysis. Attribution to a specific nation‑state or criminal organization remains uncertain; thus confidence is moderate regarding organizational attribution and adversary intent beyond financial motive. Data gaps include definitive attribution evidence, detailed weaponization chain specifics, and temporal activity of the earliest campaign phases.
No campaigns linked yet.
No observed data linked yet.
22
Techniques
45
Tools
0
Campaigns
39
IOCs
0
Observed Data
10
Tactics