• Hello and welcome! Register to enjoy full access and benefits:

    • Advertise in the Marketplace section for free.
    • Get more visibility with a signature link.
    • Company/website listings.
    • Ask & answer queries.
    • Much more...

    Register here or log in if you're already a member.

  • 🎉 WHV has crossed 56000 (56k) monthly views (unique) and 285135 clicks per month, as per Google Analytics! Thank you for your support! 🎉

ShadyPanda Browser Extensions Amass 4.3M Installs in a Massive Malicious Campaign

johny899

New Member
Content Writer
Messages
974
Reaction score
3
Points
23
Balance
$1,220.8USD
I've downloaded tons of browser extension tools, whether they're for wallpaper changing, tab management or productivity. Most recently, I downloaded a browser extension tool called "ShadyPanda" which turned out to be malware.

What Is ShadyPanda?​

ShadyPanda is the name of an online campaign that pushed out fake browser extension applications. It tricked many users into downloading them thinking they would be safe and useful. In total, ShadyPanda generated over 4.3 million downloads from Chrome and Edge browsers combined.

How Did They Turn Dangerous?​

When ShadyPanda was first released, it appeared to be normal. Therefore, it caught many people's attention. However, once users started using ShadyPanda, they slowly became malicious through:
  • Stealing browsing habits
  • Spying on users
  • Remote controlling the browser and settings
  • Secretly gathering personal information from the user
Due to how ShadyPanda initially appeared, no one suspected that it would turn out to be malicious.

How Did ShadyPanda Trick So Many People?​

ShadyPanda took advantage of many people by doing the following things to fool millions of users:
  • They pretended to be relatively normal browser tools (for example, wallpaper changers or tab managers).
  • They waited for many users to install their extensions.
  • When a large number of users had installed their extension, they pushed a silent update to turn these tools into spyware.
  • Most people did not check what permissions the extension actually needed.
What a clever way to get millions of people to fall for your ruse! This case really makes me think twice before installing anything from now on.

What You Can Do to Protect Yourself​

Here are some things you can do to help protect yourself:
  • Only install extensions you absolutely need.
  • Check the permissions they request before you install an extension.
  • Remove any extensions you do not use.
  • Be on the lookout for suspicious behavior from your browser.