Skip to main content
Mallory
MalwareUsed by 1 actor

Panda Shop

Panda Shop is a smishing toolkit associated in reporting with China-based cybercriminal activity and described as operating in a crime-as-a-service ecosystem. It has been reported as a new smishing kit that mimics the tactics and kit model of the China-linked Smishing Triad, while adding improved features and new templates. Multiple actors were reported using the kit.

Reported delivery channels include Apple iMessage and Google RCS, with additional use of SMS gateways and specialized operator-grade messaging equipment. One report specifically states the operation used compromised Apple iCloud accounts to send malicious links to counterfeit websites. Panda Shop has been described as impersonating postal and delivery services including India Post, USPS, and Royal Mail, and also using Google Wallet and Apple Pay themed lures.

Its objective is credential, payment, and personal-data theft. Reported capabilities include harvesting traditional credit card data and personally identifiable information, stealing personal and financial information via counterfeit phishing sites, and intercepting transactions. The activity has also been linked in reporting to downstream fraud including carding, NFC-enabled fraud, and money-laundering chains. Reporting characterizes the targeting as global and consumer-focused at large scale.

The kit was reportedly distributed through Telegram channels. Resecurity stated it identified vulnerabilities in the Panda Shop kit that enabled access to data associated with more than 108,000 victims. Reporting also cites threat-actor chatter claiming a single actor could send up to 2,000,000 smishing messages per day, though that figure is an unverified claim from the cited reporting rather than a confirmed operational metric.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Smishing Triad

"Resecurity found a new smishing kit called ‘Panda Shop,’ mimicking Smishing Triad tactics with improved features and new templates."

via securityaffairssecurityaffairs.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1078Valid AccountsEvidence1

By leveraging compromised Apple and Gmail accounts, the group bypasses SMS carrier detection and enhances delivery via encrypted messaging services.

T1566.003Spearphishing via ServiceEvidence1

Unlike traditional SMS phishing, which depends on mobile carriers, these actors exploit internet-based messaging systems... By leveraging compromised Apple and Gmail accounts, the group bypasses SMS carrier detection and enhances delivery via encrypted messaging services.

Persistence

1 technique
T1078Valid AccountsEvidence1

By leveraging compromised Apple and Gmail accounts, the group bypasses SMS carrier detection and enhances delivery via encrypted messaging services.

Privilege Escalation

1 technique
T1078Valid AccountsEvidence1

By leveraging compromised Apple and Gmail accounts, the group bypasses SMS carrier detection and enhances delivery via encrypted messaging services.

Stealth

2 techniques
T1036MasqueradingEvidence1

The Panda Shop operation offers a customizable smishing kit... with a suite of pre-built phishing templates impersonating brands like USPS, UPS, DHL, Vodafone, Bank of America, UK government portals.

T1078Valid AccountsEvidence1

By leveraging compromised Apple and Gmail accounts, the group bypasses SMS carrier detection and enhances delivery via encrypted messaging services.

Credential Access

1 technique
T1111Multi-Factor Authentication InterceptionEvidence1

Resecurity found that the smishing campaigns tied to Panda Shop funnel stolen credentials into underground carding shops, often through administrative panels used to track victims and intercept OTPs.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.