ShadyPanda browser extensions amass 4.3M installs in malicious campaign
ID: 881c1b6c-1d1a-5727-b613-3dd2256b4670
STIX ID: report--881c1b6c-1d1a-5727-b613-3dd2256b4670
Feed Name: Bleeping Computer
Koi Security uncovered the long-running “ShadyPanda” operation: 145 browser extensions (Chrome and Edge) that evolved from legitimate tools into spyware and a remote backdoor, accumulating millions of installs (reports cite ~4.3M total and single extensions with millions of users). The campaign progressed from affiliate fraud to search-hijacking and ultimately to an hourly remote code execution backdoor that can download and run arbitrary JavaScript, exfiltrate browsing data, cookies, keystrokes, and fingerprints to attacker domains, and has persisted on the Microsoft Edge Add-ons store despite removals from Chrome. Users are advised to remove suspicious extensions and reset passwords; researchers and platform owners were notified and Microsoft reported removing the identified Edge extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
