Skip to content
Threat Feed
high advisory

PanDa Android RAT Campaign Targeting Mexican Financial Users

Chinese-speaking threat actors are using the AppPanda phishing platform to distribute the PanDa Android RAT via Meta Ads, targeting Spanish-speaking users in Mexico to harvest banking credentials.

Intel 471 has identified a coordinated, large-scale phishing operation utilizing a management platform dubbed AppPanda to distribute the PanDa Android remote access trojan (RAT). Since May 2026, the campaign has targeted Spanish-speaking users in Mexico through Meta Ads, masquerading as legitimate streaming services such as Netflix, NovaFlix, and various fictitious brands. The infrastructure supports an as-a-service model, allowing affiliates to generate malicious APK payloads via an 'APK Factory' and manage ad attribution through 'Appchi'. PanDa is a sophisticated spyware capable of screen streaming, hidden virtual network computing (HVNC), keylogging, and remote device control. By abusing Android accessibility services, the malware targets credentials from over 62 banking and financial institutions in Mexico and Nigeria. The operation is highly scalable, with one week of activity in July 2026 resulting in nearly 15,000 malicious app downloads.

Attack Chain

  1. Attacker creates malicious Meta Ads impersonating popular streaming services to attract Mexican mobile users.
  2. Victim clicks the advertisement, resolving to a 'jump domain' that redirects to an AppPanda-managed phishing site.
  3. Victim downloads a malicious APK file, tracked as the 'ShellA' loader, masquerading as a streaming application.
  4. The loader prompts the victim to enable 'install from unknown sources' in system settings to facilitate the secondary payload installation.
  5. ShellA decrypts hidden files, randomizes its internal signature to evade hash-based detection, and installs the final PanDa RAT APK.
  6. PanDa launches and requests 'accessibility services' permissions, which the attacker abuses to capture credentials and monitor sensitive interactions.
  7. The malware establishes a non-encrypted WebSocket connection to the command-and-control (C2) server for data exfiltration and remote command reception.
  8. The attacker uses the C2 to remotely control the device, perform keylogging, or stream the screen to harvest financial login information.

Impact

The PanDa campaign poses a significant threat to mobile banking customers, with documented targeting of 62 financial institutions. The successful deployment of the RAT grants attackers full surveillance capabilities, including the ability to bypass typical security controls via HVNC and accessibility service abuse. The scale of the operation - over 350,000 landing page visits and 15,000 downloads in a single week - indicates a persistent and highly effective threat to the financial sector in the targeted regions.

Recommendation

Prioritize the following actions to detect and mitigate the AppPanda operation:

  • Block the documented phishing domains at the enterprise DNS resolver or proxy layer.
  • Implement mobile device management (MDM) policies to restrict the installation of applications from unknown sources on corporate-managed devices.
  • Monitor for unusual WebSocket traffic patterns originating from mobile endpoints to unknown or suspicious IP ranges.
  • Review network logs for outbound traffic to the phishing domains identified in the IOC table.
  • Conduct user awareness training specifically targeting 'malvertising' and suspicious streaming app promotions on social media platforms.

Immediate actions

Block identified phishing domains at the DNS level.

SOC 24h

Threat Hunt

Identify Android devices within the network performing unauthorized external connections to suspicious streaming domains.

T1566.003 high high confidence hunt now

Data: DNS query logs, Proxy logs

Mitigations

Enable MDM policies to block 'Install from Unknown Sources' on corporate mobile devices.

immediate IT Operations

Android platform infection vector

Indicators of compromise

12

domain

TypeValue
domainalvoplay.com
domainceloloplay.com
domaincineviabox.com
domainevotiprime.com
domainfarorelive.com
domainhalogobox.com
domainhalonanow.com
domainnovaoraprime.com
domainpicomiplay.com
domainrivasatv.com
domainultratv.com
domainvivaplay.com