12/02/2025
đź ShadyPandaâs Seven-Year Sleep: 4.3 Million Users Targeted by Malicious Browser Extensions
Cybersecurity researchers at Koi Security have uncovered a massive, long-running campaign by a threat actor known as ShadyPanda. Over seven years, this group infiltrated Chrome and Edge browsers through seemingly harmless extensions, amassing 4.3 million installs before deploying spyware and backdoors.
Phase 1: Building Trust (2018â2022)
ShadyPanda began publishing extensions in Google Chrome and in Firefox under innocent themesâwallpaper managers, productivity toolsâearning glowing reviews and âFeaturedâ badges. This strategy built credibility and lulled users into a false sense of security. ShadyPanda had been producing viable, sought after product for 4 years! Credibility is everything nowadays.
Phase 2: Affiliate Fraud (2023)
The first malicious activity appeared in 2023: silent affiliate code injection.
đź ShadyPandaâs Seven-Year Sleep: 4.3 Million Users Targeted by Malicious Browser Extensions Cybersecurity researchers at Koi Security have uncovered a m