Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
2 malware families

DarkSpectre

Also known asdarkspectre

DarkSpectre is a Chinese or China-linked threat actor tracked by Koi Security and described in the content as responsible for large-scale malicious browser-extension operations affecting more than 8.8 million users over more than seven years across Chrome, Edge, Firefox, and Opera. The actor is associated with at least three campaigns: ShadyPanda, GhostPoster, and Zoom Stealer (also referred to as The Zoom Stealer). Some content also describes the group as a cybercriminal group and as Chinese affiliated/China-based. ShadyPanda is described as a long-running browser-extension campaign targeting Chrome, Edge, and Firefox users for data theft, search-query hijacking, browsing surveillance, and affiliate fraud. The campaign reportedly affected about 5.6 million users. The content states that some extensions behaved normally for years before becoming malicious after an update, including time-delayed or logic-bomb activation intended to evade store review. Researchers reported 9 active malicious extensions and roughly 85 dormant or sleeper extensions intended for later weaponization. GhostPoster is described as a campaign primarily targeting Firefox users, though some reporting says it first targeted Edge and later expanded to Chrome and Firefox. It used benign-looking utility and VPN-themed extensions published in official browser stores. The campaign delivered malicious JavaScript for affiliate-link hijacking, tracking-code injection, click fraud, and ad fraud. The content states GhostPoster used steganography to hide JavaScript payloads inside extension image assets, including PNG icons, with newer variants decoding and decrypting payloads at runtime to hinder detection. An Opera extension tied to GhostPoster, presented as Google Translate and published by "charliesmithbons," is described as having nearly 1 million installs. Zoom Stealer/DarkSpectre is described as a campaign using 18 browser extensions across Chrome, Edge, and Firefox, affecting about 2.2 million users. The extensions impersonated or mimicked enterprise videoconferencing and related utility tools and requested access to more than 28 conferencing platforms, including Zoom, Microsoft Teams, Google Meet, Cisco WebEx, and GoTo Webinar. The content states the extensions exfiltrated meeting intelligence in real time over WebSockets, including meeting URLs with embedded passwords, meeting IDs, topics, descriptions, scheduled times, registration status, participant data, and webinar speaker/host details such as names, titles, bios, profile photos, company affiliations, logos, promotional graphics, and session metadata. Researchers characterized this as corporate-espionage infrastructure and systematic collection of corporate meeting intelligence. Attribution indicators cited in the content for a Chinese nexus include Alibaba Cloud-hosted command-and-control infrastructure, ICP registrations tied to Chinese provinces including Hubei, Chinese-language strings and comments in code, activity patterns matching the Chinese timezone, and fraud/monetization targeting Chinese e-commerce platforms such as JD.com and Taobao.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics11 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1195
Supply Chain Compromise
T1195.002
Compromise Software Supply Chain
TA0003
Persistence
2 techniques
T1176×2
Software Extensions
T1546
Event Triggered Execution
T1546.003
Windows Management Instrumentation Event Subscription
TA0004
Privilege Escalation
1 technique
T1546
Event Triggered Execution
T1546.003
Windows Management Instrumentation Event Subscription
TA0005
Stealth
1 technique
T1027
Obfuscated Files or Information
T1027.003
Steganography
TA0006
Credential Access
1 technique
T1555
Credentials from Password Stores
TA0007
Discovery
1 technique
T1217
Browser Information Discovery
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping7

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.

DarkSpectre | Mallory