ShadyPanda played the long game, waiting years to infect 4 million browsers with spyware

When you think of a cyber attack, I’m going to bet that many readers will imagine it’s a reasonably quick process: send a phishing email, compromise account credentials, take over the account, and deploy a payload. All of which can be done pretty much automatically, thanks to the wonders of AI.

Sure, this isn’t always the case, and higher-value victims can justify spending more time to ensure the initial access phase is successful, including victim reconnaissance and targeted spear-phishing. But a week is a heck of a long time in cybercrime, and tempus est pecunia.

Which is a long-winded way of getting to the point that some threat actors are willing to play the long game. The very long game in the case of ShadyPanda, a group that is thought to be China-affiliated. How does seven years strike you? Yes, you read that right.

ShadyPanda’s seven-year wait

Tuval Admoni is a security researcher with the Koi cyber security and network analyst team. In a new report, he said that ShadyPanda is responsible for “a seven-year browser extension campaign that has infected 4.3 million Chrome and Edge users”.

The Koi researchers uncovered a four-million-user spyware operation that used malicious browser extensions to send data to servers in China that included “every URL visited, search query, and mouse click”.

ShadyPanda screenshot of infected add-on
Clean Master is one of the add-ons identified by Koi

But that’s not all. The investigation also found a 300,000-user remote code execution (RCE) backdoor using extensions that were “weaponised in mid-2024 after years of legitimate operation”.

Every hour, these extensions downloaded and executed arbitrary JavaScript that monitored website visits, exfiltrated encrypted browsing history, and collected browser fingerprints.

“Some of ShadyPanda’s extensions were featured and verified by Google,” Admoni warned, “granting instant trust and massive distribution.”

Industry response to ShadyPanda

A Google spokesperson said that none of the extensions are available on the Chrome Web Store any longer, and Google’s screening checks for any and every update to extensions. 

But Diane Downie, Senior Software Architect at Black Duck, told TechFinitive that organisations need to adopt a zero-trust posture across their systems as malicious code “poses a real challenge since it closely resembles legitimate code, leveraging the same convenience features but with bad intent”.

What’s more, Downie warned, “bad actors have strong incentives to play the long game in a landscape where almost everything is software-enabled”.

“ShadyPanda demonstrated their commitment to long-term strategies by releasing clean extensions that garnered hundreds of thousands of installs,” said Randolph Barr, Chief Information Security Officer at Cequence Security.

“Their plan was simple: first, earn trust, then use it. And it worked.”

That ShadyPanda was happy to play a seven-year-long game should be a wake-up call to enterprises, as it “emphasises the reality that browser extension ecosystems remain one of the least controlled and most vulnerable areas of the modern enterprise attack surface,” Barr concluded.

More from Davey Winder

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.