Panda Shop is a China-based cybercriminal smishing and phishing-as-a-service operation that provides crime-as-a-service tooling, infrastructure, and support to fraud actors. It is associated with the Chinese-language phishing ecosystem and has been described as part of, or closely aligned with, the broader Smishing Triad ecosystem alongside kits such as Darcula, Lucid, and Lighthouse. Panda Shop uses Telegram channels and bots to automate customer onboarding, service delivery, and support, and offers customizable phishing templates, administration panels, setup assistance, and operational guidance. The operation specializes in large-scale mobile-centric phishing and smishing campaigns delivered through internet messaging channels such as Apple iMessage and Android RCS rather than relying solely on traditional SMS. Its phishing pages impersonate commercial brands, logistics providers, financial institutions, and government services in order to steal payment card data, personally identifiable information, credentials, and one-time passwords. Panda Shop has also been linked to real-time phishing workflows in which victim inputs are intercepted and relayed for immediate fraudulent use. Panda Shop supports downstream fraud and monetization activity beyond credential collection. Stolen payment data and personal information are funneled into carding and fraud ecosystems, including merchant fraud, mobile wallet abuse, and cash-out operations. Reporting also links Panda Shop-enabled activity to Google Wallet and Apple Pay fraud and to broader money-laundering and mule-enabled monetization chains. In the Chinese-language underground, Panda Shop has been connected to resale and proxy-phishing services and to Telegram-based criminal market infrastructure used for escrow, coordination, and contracting. Targeting has included Japan, the United States, and the United Kingdom, with notable overlap between Panda Shop activity and campaigns aimed at Japanese organizations and Japanese financial or securities-related victims. The group’s tradecraft emphasizes scalable initial access through spoofed mobile messages, credential theft, session-adjacent real-time interception of authentication data, exfiltration of victim information, and operational support for fraud at industrial scale. The actor’s dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-language phishing-as-a-service provider whose services were used for proxy sales and proxy phishing operations tied to real-time phishing activity.
A Chinese cybercriminal group operating a customizable smishing kit and crime-as-a-service platform, automating phishing and carding activities, and distributing phishing messages via compromised accounts.
Carding/smishing operation at scale (as characterized in the referenced title).
China-based cybercriminal syndicate operating a smishing-focused crime-as-a-service platform used for carding, merchant fraud, personal data theft, OTP interception, and NFC-enabled payment fraud via Apple iMessage, Android RCS, and Telegram-supported infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.