DarkSpectre
DarkSpectre is a Chinese or China-linked threat actor tracked by Koi Security and described in the content as responsible for large-scale malicious browser-extension operations affecting more than 8.8 million users over more than seven years across Chrome, Edge, Firefox, and Opera. The actor is associated with at least three campaigns: ShadyPanda, GhostPoster, and Zoom Stealer (also referred to as The Zoom Stealer). Some content also describes the group as a cybercriminal group and as Chinese affiliated/China-based. ShadyPanda is described as a long-running browser-extension campaign targeting Chrome, Edge, and Firefox users for data theft, search-query hijacking, browsing surveillance, and affiliate fraud. The campaign reportedly affected about 5.6 million users. The content states that some extensions behaved normally for years before becoming malicious after an update, including time-delayed or logic-bomb activation intended to evade store review. Researchers reported 9 active malicious extensions and roughly 85 dormant or sleeper extensions intended for later weaponization. GhostPoster is described as a campaign primarily targeting Firefox users, though some reporting says it first targeted Edge and later expanded to Chrome and Firefox. It used benign-looking utility and VPN-themed extensions published in official browser stores. The campaign delivered malicious JavaScript for affiliate-link hijacking, tracking-code injection, click fraud, and ad fraud. The content states GhostPoster used steganography to hide JavaScript payloads inside extension image assets, including PNG icons, with newer variants decoding and decrypting payloads at runtime to hinder detection. An Opera extension tied to GhostPoster, presented as Google Translate and published by "charliesmithbons," is described as having nearly 1 million installs. Zoom Stealer/DarkSpectre is described as a campaign using 18 browser extensions across Chrome, Edge, and Firefox, affecting about 2.2 million users. The extensions impersonated or mimicked enterprise videoconferencing and related utility tools and requested access to more than 28 conferencing platforms, including Zoom, Microsoft Teams, Google Meet, Cisco WebEx, and GoTo Webinar. The content states the extensions exfiltrated meeting intelligence in real time over WebSockets, including meeting URLs with embedded passwords, meeting IDs, topics, descriptions, scheduled times, registration status, participant data, and webinar speaker/host details such as names, titles, bios, profile photos, company affiliations, logos, promotional graphics, and session metadata. Researchers characterized this as corporate-espionage infrastructure and systematic collection of corporate meeting intelligence. Attribution indicators cited in the content for a Chinese nexus include Alibaba Cloud-hosted command-and-control infrastructure, ICP registrations tied to Chinese provinces including Hubei, Chinese-language strings and comments in code, activity patterns matching the Chinese timezone, and fraud/monetization targeting Chinese e-commerce platforms such as JD.com and Taobao.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese threat actor behind multiple malicious browser extension campaigns (ShadyPanda, GhostPoster, DarkSpectre) impacting millions of users.
Runs a browser-extension campaign (GhostPoster cluster) targeting Chrome/Edge (and later Firefox) to hijack affiliate links, inject tracking code, and conduct click/ad fraud at scale.
Cybercriminal group operating malicious browser-extension campaigns (ShadyPanda, GhostPoster, Zoom Stealer). Tactics include pushing malicious updates to previously benign extensions, monitoring browsing activity, and deploying backdoor-capable JavaScript. GhostPoster notably uses steganography to hide JavaScript payloads inside extension image assets (e.g., PNG icons), with newer variants embedding, decoding, and decrypting payloads at runtime to evade detection. Campaign expanded across Edge to Chrome and Firefox via official web stores using seemingly legitimate utility extension names.
DarkSpectre is a China-linked threat actor running coordinated, large-scale malicious browser extension campaigns for surveillance, fraud, and espionage.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.