Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

ShadyPanda

ShadyPanda is a large-scale spyware campaign centered on malicious browser extensions. The provided content describes it as a China-linked operation and a flagship campaign associated with the threat actor DarkSpectre. Researchers assessed the activity as long-running, spanning more than seven years, and affecting Chrome, Microsoft Edge, and Firefox users. One cited report states ShadyPanda weaponized trusted browser extensions via auto-updates and infected over 4.3 million users globally; another summary in the content describes the broader ShadyPanda campaign as involving 5.6 million users across more than 100 extensions.

According to the content, ShadyPanda relied on long-lived extensions that presented themselves as legitimate productivity tools while functioning as comprehensive spyware. The campaign allegedly included 9 actively malicious extensions and more than 85 dormant sleeper extensions awaiting weaponization. A key operational feature was configuration-based command-and-control, allowing operators to change extension behavior server-side without pushing new extension updates. The activity is described as enabling large-scale surveillance and remote control.

The content links ShadyPanda to infrastructure patterns shared with other DarkSpectre campaigns. Researchers reportedly pivoted from domains such as infinitynewtab.com and infinitytab.com to identify connected extensions, and identified a jt2x.com cluster in which extensions used api.jt2x.com for C2, configuration downloads, data exfiltration, and affiliate fraud. The reporting also notes attribution indicators cited for a Chinese nexus, including Alibaba Cloud hosting in China, ICP registrations linked to Chinese provinces including Hubei, Chinese-language code artifacts, and affiliate-fraud targeting of JD.com and Taobao.

High-confidence indicators and related references mentioned in the content include infinitynewtab.com, infinitytab.com, api.jt2x.com, and the campaign name ShadyPanda itself. The visible headline-only source also associates the campaign with browser-extension auto-update abuse, Chrome Web Store exposure, and tags including backdoor and RCE, but that source does not provide technical detail beyond the headline and metadata.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.