12/02/2025
š¼ ShadyPandaās Seven-Year Sleep: 4.3 Million Users Targeted by Malicious Browser Extensions
Cybersecurity researchers at Koi Security have uncovered a massive, long-running campaign by a threat actor known as ShadyPanda. Over seven years, this group infiltrated Chrome and Edge browsers through seemingly harmless extensions, amassing 4.3 million installs before deploying spyware and backdoors.
Phase 1: Building Trust (2018ā2022)
ShadyPanda began publishing extensions in Google Chrome and in Firefox under innocent themesāwallpaper managers, productivity toolsāearning glowing reviews and āFeaturedā badges. This strategy built credibility and lulled users into a false sense of security. ShadyPanda had been producing viable, sought after product for 4 years! Credibility is everything nowadays.
Phase 2: Affiliate Fraud (2023)
The first malicious activity appeared in 2023: silent affiliate code injection.
š¼ ShadyPandaās Seven-Year Sleep: 4.3 Million Users Targeted by Malicious Browser Extensions Cybersecurity researchers at Koi Security have uncovered a m