Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads Malvertising — Threadlinqs Intelligence
As of 2026-09-01, Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads Malvertising is a high-severity malware threat attributed to Chinese-speaking threat cluster, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-2279 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Chinese-speaking threat cluster · FINANCIAL
Intel 471 reports Chinese-speaking threat actors targeting Spanish-speaking Android users in Mexico (secondary targeting in Nigeria) with the PanDa remote access Trojan, delivered by the ShellA loader
PanDa is a newly documented Android remote access trojan tracked by Intel 471, deployed by a Chinese-speaking threat cluster (attributed via Chinese-language text throughout the AppPanda phishing management panel) against Spanish-speaking Android users, primarily in Mexico with secondary targeting in Nigeria. Since at least May 2026, victims have been lured through Meta Ads (Facebook/Instagram) linking to phishing landing pages that initially impersonated Netflix. In July 2026 Intel 471 observed the actors shift tactics, launching campaigns impersonating a new fictitious brand, NovaFlix, alongside a growing list of additional fictitious streaming-service brands that ultimately included AlvoPlay, CeloloPlay, CineviaBox, EvotiPrime, FaroreLive, HalogoBox, HalonaNow, NovaoraPrime, PicomiPlay, RivasaTV, UltraTV, and VivaPlay. In August 2026 a further campaign wave impersonated Netflix and other legitimate streaming services. Victims who enable "install from unknown sources" are prompted to install the ShellA loader APK, which verifies sideloading is already enabled, decrypts and installs a bundled PanDa payload via dynamic APK reassembly with a per-build randomized signature, and, once installation completes, launches PanDa and requests Android Accessibility Services permission.
Once Accessibility Services access is granted, PanDa gives operators keylogging (stealing credentials entered into banking-app login pages), screen streaming/HVNC (hidden virtual network computing) for live device viewing and remote control, screen-lock capture, and device settings manipulation, communicating with its command-and-control infrastructure over an unencrypted WebSocket connection. The malware dynamically enumerates installed application package names to identify which of 62 targeted banks and financial institutions across Mexico and Nigeria are present on the victim device before selectively harvesting credentials.
The campaign runs on a fully operationalized criminal infrastructure ecosystem centered on the AppPanda panel: a Chinese-language phishing management dashboard that, per Intel 471's review, had 11 configured landing-page templates (each defining a phishing-page title, visual theme, domain name, and associated malicious APK payload) alongside campaign-traffic statistics and automated registration of new phishing domains. AppPanda is fed by the APK Factory payload-builder service (which also generates the unrelated BTMOB Android banking trojan), the BAT1688 crypting/obfuscation platform (which re-signs PanDa payload APKs roughly every 60 minutes to defeat hash-based antivirus detection), and the Appchi ("Pixel Center") Facebook ad-campaign management interface, which is integrated with the HuiTongCard virtual payment service for tracking ad spend and uses disposable "jump domains" embedded in the Meta ad units to shield the phishing infrastructure from takedown. Over a single tracked one-week window beginning July 2, 2026, the AppPanda panel logged more than 350,000 landing-page visits, 200,000 unique visitors, and nearly 15,000 malicious APK downloads across at least 22 newly registered phishing domains. Operators tracked install conversion using the PromoLink attribution identifier and Facebook Click Identifier embedded in the ad links to resolve APK payload URLs; by August 2026 they had added Facebook Pixel SDK integration to further optimize which ads drove the most downloads.
Intel 471 assesses the campaign as active and ongoing as of its September 1, 2026 disclosure, anticipating expansion into additional geographic regions, and recommends correlating live C2 traffic, infrastructure pivots, and newly registered phishing domains (via tooling such as its Retroactive Threat Detection capability and Brand Exposure module) for early detection.
This campaign fits a broader 2026 pattern of Meta-Ads-delivered Android RATs targeting Spanish-speaking users via streaming- and finance-app lures — including the unrelated Mirax RAT campai
Target sectors: financial services, banking, streaming media impersonated, consumer mobile users
Target regions: mexico, nigeria
Timeline
- PanDa RAT campaign first observed spreading through Meta Ads, luring Spanish-speaking Android users in Mexico to download and install a malicious application masquerading as the Netflix app.
- Intel 471 observes the actors shift tactics in July, launching campaigns impersonating a new fictitious brand, NovaFlix, alongside a growing list of additional fictitious streaming brands (eventually including AlvoPlay, CeloloPlay, CineviaBox, EvotiPrime, FaroreLive, HalogoBox, HalonaNow, NovaoraPrime, PicomiPlay, RivasaTV, UltraTV, and VivaPlay) to deliver PanDa via ShellA-loader phishing pages.
- Start of a one-week tracked campaign window; the AppPanda panel's 11 configured landing-page templates (title, theme, domain, payload) begin logging traffic and automated phishing-domain registration.
- The one-week tracked window (July 2-9, 2026) closes with more than 350,000 landing-page visits, 200,000 unique visitors, and nearly 15,000 malicious APK downloads logged across at least 22 phishing domains registered during the period.
- A new campaign wave impersonates Netflix and other legitimate streaming services; operators add Facebook Pixel SDK integration alongside the existing PromoLink attribution identifier and Facebook Click Identifier used to resolve APK payload URLs and optimize which ads drive the highest install-conversion rate.
- Intel 471 publishes full campaign analysis attributing the AppPanda/APK Factory/BAT1688 infrastructure ecosystem to a Chinese-speaking threat cluster (based on Chinese-language UI throughout the AppPanda panel), assesses the campaign as active and ongoing, and anticipates future campaigns expanding into additional geographic regions and adopting new phishing-page themes tailored to local audiences.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1660, T1655.001, T1406.002, T1629.003, T1626, T1417.001, T1513, T1516, T1437.001, T1418