SYMBOLCOMMON_NAMEaka. SYNONYMS

ShadyPanda  (Back to overview)


ShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity tools while functioning as comprehensive spyware. Their tactics include data exfiltration, user surveillance, and systematic collection of corporate meeting intelligence from over 28 video conferencing platforms. Notably, the WeTab extension exemplifies their capabilities, collecting full browsing history and personal data, exfiltrating to 17 different domains. The actor employs steganography to hide malicious code within PNG files and maintains persistent access through shared infrastructure across their extensions.


Associated Families

There are currently no families associated with this actor.


References
2025-12-30Koi SecurityGal Hachamov, Tuval Admoni
DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers
ShadyPanda
2025-12-01Koi SecurityTuval Admoni
4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign
ShadyPanda

Credits: MISP Project