Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
1 malware family

ShadyPanda

Also known asshadypanda

ShadyPanda is a threat actor tracked by Koi Security for a long-running browser extension campaign targeting Google Chrome and Microsoft Edge users. The group is described in the content as likely China-based or China-linked, although some reporting notes that China attribution is suspected but not confirmed. ShadyPanda conducted a methodical campaign lasting roughly seven years and infected more than 4.3 million browser instances by publishing seemingly legitimate extensions, building trust and install volume over time, and then pushing malicious updates through trusted browser marketplace auto-update mechanisms. The group used over 100 malicious extensions, including 20 Chrome extensions and 125 Edge extensions in earlier phases, and later weaponized popular extensions such as Clean Master and WeTab. Some extensions reportedly received marketplace trust indicators such as Featured or Verified status before being turned malicious. The campaign evolved across multiple phases: early activity involved affiliate fraud by injecting tracking codes into sites such as eBay, Amazon, and Booking.com; later activity included browser hijacking, search redirection, cookie theft, and keystroke harvesting; and subsequent phases added spyware and a backdoor capable of remote code execution by downloading and executing arbitrary JavaScript with full browser API access. Reported collection and surveillance activity included browsing history, URLs visited, search queries, mouse clicks, browser fingerprints, session data, cookies, and other browser telemetry. The content also states that ShadyPanda manipulated search results and traffic, used man-in-the-browser-style techniques, and exfiltrated data to infrastructure described as being in China. The malware reportedly used obfuscation and anti-analysis behavior, including switching to benign behavior when developer tools were opened. The campaign relied on trusted browser marketplaces and weak post-approval monitoring rather than phishing or social engineering. Known aliases and related labels directly mentioned in the content are limited to ShadyPanda. Developer or publisher names associated with parts of the campaign in the reporting include nuggetsno15, Zhang, rocket Zhang, and Starlab Technology, but these are described as publisher identities used in the operation rather than confirmed subgroup names.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics4 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1195×2
Supply Chain Compromise
TA0002
Execution
1 technique
T1203
Exploitation for Client Execution
TA0006
Credential Access
1 technique
T1555
Credentials from Password Stores
TA0009
Collection
1 technique
T1185
Browser Session Hijacking
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping4

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.