Security1 distinct publisher2 min readPublished
Intel 471 found an unauthenticated panel called AppPanda running fake streaming lures behind paid Facebook ads, with affiliate tooling that re-signs the Android payload every hour and tracks ad spend the way a growth team would.
The Watch · Security desk
product
Pennsylvania's Snap case makes an App Store questionnaire the alleged lie1 distinct publisher
build
GitVenom dressed hundreds of repositories over several years to ship AsyncRAT and Quasar1 distinct publisher
security
The fake Indeed interview app that stops you uninstalling it1 distinct publisher
product
Nebius funds $4.5bn of AI capacity on terms that pay lenders mostly in stock2 distinct publishers
Compiled by The WatchSomething wrong?How this is made
Seven and a half percent of the people who reached one of these landing pages installed the app. Intel 471's numbers, read off the operators' own panel, put 200,000 unique visitors against nearly 15,000 downloads in the week beginning July 2, 2026 [8][1]. For a sideloaded APK that requires the victim to go and disable a security setting, that is a high conversion rate, and paid placement is the reason. Meta's targeting delivers people already shopping for a streaming app, and in August the operators wired in the Facebook Pixel SDK so ad attribution could be measured properly [6].
The install chain has one hard step, and it is consent. ShellA, the loader, asks the victim to toggle the setting that permits installs from outside Google Play, presented as a requirement for smooth playback in the fake Netflix app, with prompt text and layout matched to the lure page [4][15]. After that PanDa holds screen streaming, hidden VNC, remote control, keylogging and screen-lock capture [2]. That is an interactive session on the handset rather than a credential dump, and the same builder service that produces PanDa also produces BTMOB, a banking trojan [11].
BAT1688 re-obfuscates and re-signs payloads on a 60-minute rotation [12]. That works out to 24 builds a day and 168 a week [2], which means a hash or static signature for this family expires before the ticket gets triaged. The control that maps to the mechanism is the install-source restriction itself, because that toggle is the step the malware needs a human to perform [15].
Provenance here comes down to two separate points. The attribution is language evidence: Intel 471 says Chinese used throughout the panel suggests the infrastructure was built or maintained by Chinese-speaking actors, which is not a named group [9]. And the traffic figures are the operators' own counters, visible only because the AppPanda panel required no authentication when researchers followed a tracking URL into it [7]. No second publisher has confirmed them.
The takedown surface is the weak part of the defensive story. At least 22 phishing domains were registered inside that one week [8], averaging roughly 15,900 visits and 682 downloads each [3], and disposable jump domains embedded in the ads absorb the losses while shielding the core infrastructure [14]. Brand rotation covered four months, from the Netflix lure in May to NovaFlix and invented streaming names in July and back to Netflix imitations in August [3][5][6][4]. The pieces that persist across all of it are the Facebook ad accounts and the HuiTongCard virtual payment service the operators use to fund them [13].
Ranked by verification strength, evidence, and original report placement.
Intel 471 Malware Intelligence researchers uncovered a phishing operation that used Meta Ads to distribute a newly identified Android remote access trojan, tracked as PanDa, targeting Spanish-speaking users in Mexico.
PanDa provides screen streaming, hidden virtual network computing (HVNC) and remote control, keylogging, screen lock capture and control of infected device settings.
The PanDa-associated phishing campaign was first observed in May 2026, spreading through Meta Ads with lures for Spanish-speaking users in Mexico to install a malicious application masquerading as the Netflix app.
The downloaded APK, tracked as ShellA, serves as a loader for PanDa.
In July 2026 the actors shifted tactics, launching campaigns impersonating NovaFlix and a growing list of fictitious streaming brands to deliver PanDa.
In August a new campaign wave impersonated Netflix and other legitimate streaming services, with the actors introducing the Facebook Pixel SDK into malvertising campaigns to improve ad-attribution tracking.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One researcher, reading the attackers' own instruments
The 350,000 visits, the 22 domains, the 11 templates — all of it is read off a panel the operators forgot to put a password on, screenshotted and dated by Intel 471. As malware reporting goes that is unusually direct material, and it is also entirely unverified: no second team confirms the counters, neither Meta nor Google is quoted on the ads or on Play Protect, and Intel 471's write-up offers no indicators anyone could independently hunt with.
A funnel in production, not a lab curiosity
Judge this operation the way you would judge a product launch and it is doing well: four months of lure iteration from fake Netflix through NovaFlix and back, roughly 7.5 percent of unique visitors taking the download, nearly 15,000 of them in a single week over 22 domains, a builder that already serves a second malware family, and a keylogger configured for 62 banks in two countries. The one caveat is that a download is not an infection, and nobody counts what happened after install.
Downloads promoted to installs, suspicion promoted to attribution
Two small inflations, both in the framing rather than the research. The panel counted downloads; our headline calls them installs, and PanDa's own loader has to talk the victim through a sideloading toggle before anything runs — a step that surely sheds users. And the title states Chinese-speaking authorship as fact where the body rests it on one thing: the panel's menus are in Chinese. The technical body of the work is not oversold; the packaging is a notch ahead of it.
The naming rights are part of the product
Intel 471 sells threat intelligence, and this piece does what vendor research does: it christens PanDa and ShellA, catalogues an ecosystem only its analysts have seen, and demonstrates the reach of its Malware Intelligence collection. That is a legitimate reason to publish and also a reason the scale figures were quoted rather than caveated. Worth noting who is silent: Meta's ad review and Google's Play Protect are both implicated in the delivery chain and neither is given a line.
Trust the mechanics, hold the numbers loosely
The loader chain, the hourly re-signing, the affiliate console and the accessibility-service theft are described concretely enough to act on, and dated screenshots back the timeline. The volume metrics and the actor attribution are softer — one vendor, one panel, one language clue — so we would report the tradecraft with confidence and the 15,000 figure with the word 'logged' attached.