WeTab is a malicious browser extension described by Koi as part of the long-running ShadyPanda malicious extension operation, which researchers assess is linked to a well-funded Chinese-linked actor. It is characterized as spyware disguised as a productivity tool and was reported to have about three million installs on Microsoft Edge. According to the provided reporting, WeTab collects extensive browser telemetry and user activity data, including visited URLs, search queries, mouse-click tracking, browser fingerprinting, page interaction data, and storage access. The content states that this data is transmitted in real time to 17 domains, including Baidu infrastructure in China, WeTab-controlled servers in China, and Google Analytics. More broadly, the surrounding ShadyPanda activity involved publishing legitimate-looking extensions, building trust over years, and later weaponizing them via updates or configuration-based control. The campaign targeted Chrome and Edge users and is associated with surveillance, data exfiltration, and potential future weaponization using backdoor capabilities seen elsewhere in the same cluster. High-confidence indicators directly mentioned for WeTab include its name, its approximate install base, its spyware-like collection of browsing and interaction data, and real-time exfiltration to 17 domains including China-based infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A spyware-like browser extension disguised as a productivity tool. It collects extensive telemetry (visited URLs, search queries, mouse clicks, browser fingerprinting, page interaction data, and storage access) and exfiltrates it in real time to multiple domains, including infrastructure in China and Google Analytics.
A spyware-capable browser extension within the ShadyPanda arsenal that performs extensive user surveillance (browsing history, search queries, click tracking) and exfiltrates data to multiple domains including infrastructure in China and analytics endpoints.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.