ShadyPandaShadyPanda

Also known as: ShadyPanda

Known aliases
1

Profile

ShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity tools while functioning as comprehensive spyware. Their tactics include data exfiltration, user surveillance, and systematic collection of corporate meeting intelligence from over 28 video conferencing platforms. Notably, the WeTab extension exemplifies their capabilities, collecting full browsing history and personal data, exfiltrating to 17 different domains. The actor employs steganography to hide malicious code within PNG files and maintains persistent access through shared infrastructure across their extensions.

Aliases· 1

ShadyPanda

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
SharpPanda
Actor
SABRE PANDA
Actor
ShaggyPanther
Actor
SAMURAI PANDA
Actor
Evasive Panda
Actor
MUSTANG PANDA
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.