Trending Topics

ShadyPanda played the long game, waiting years to infect 4 million browsers with spyware
When you think of a cyber attack, I’m going to bet that many readers will imagine it’s a reasonably quick process: send a phishing email, compromise account credentials, take over the account, and deploy a payload. All of which can be done pretty much automatically, thanks to the wonders of AI.
Sure, this isn’t always the case, and higher-value victims can justify spending more time to ensure the initial access phase is successful, including victim reconnaissance and targeted spear-phishing. But a week is a heck of a long time in cybercrime, and tempus est pecunia.
Which is a long-winded way of getting to the point that some threat actors are willing to play the long game. The very long game in the case of ShadyPanda, a group that is thought to be China-affiliated. How does seven years strike you? Yes, you read that right.
ShadyPanda’s seven-year wait
Tuval Admoni is a security researcher with the Koi cyber security and network analyst team. In a new report, he said that ShadyPanda is responsible for “a seven-year browser extension campaign that has infected 4.3 million Chrome and Edge users”.
The Koi researchers uncovered a four-million-user spyware operation that used malicious browser extensions to send data to servers in China that included “every URL visited, search query, and mouse click”.

But that’s not all. The investigation also found a 300,000-user remote code execution (RCE) backdoor using extensions that were “weaponised in mid-2024 after years of legitimate operation”.
Every hour, these extensions downloaded and executed arbitrary JavaScript that monitored website visits, exfiltrated encrypted browsing history, and collected browser fingerprints.
“Some of ShadyPanda’s extensions were featured and verified by Google,” Admoni warned, “granting instant trust and massive distribution.”
Industry response to ShadyPanda
A Google spokesperson said that none of the extensions are available on the Chrome Web Store any longer, and Google’s screening checks for any and every update to extensions.
But Diane Downie, Senior Software Architect at Black Duck, told TechFinitive that organisations need to adopt a zero-trust posture across their systems as malicious code “poses a real challenge since it closely resembles legitimate code, leveraging the same convenience features but with bad intent”.
What’s more, Downie warned, “bad actors have strong incentives to play the long game in a landscape where almost everything is software-enabled”.
“ShadyPanda demonstrated their commitment to long-term strategies by releasing clean extensions that garnered hundreds of thousands of installs,” said Randolph Barr, Chief Information Security Officer at Cequence Security.
“Their plan was simple: first, earn trust, then use it. And it worked.”
That ShadyPanda was happy to play a seven-year-long game should be a wake-up call to enterprises, as it “emphasises the reality that browser extension ecosystems remain one of the least controlled and most vulnerable areas of the modern enterprise attack surface,” Barr concluded.
More from Davey Winder
- Use ASUS routers or computers? Get these updates now as critical vulnerabilities confirmed | TechFinitive
- Latest Have I Been Pwned update gives 1.3 billion new reasons to stop relying on passwords
- Internet down — the cloudy lessons from Azure and AWS outages
- Writing down your incident response plans isn’t the cyber-antichrist of secure strategies
