Chinese-speaking threat actors targeting Mexican Android users with remote access Trojan

Intel 471 Malware Intelligence researchers recently uncovered a sprawling phishing operation that used Meta Ads to distribute a newly identified Android remote access trojan (RAT) targeting Spanish-speaking users in Mexico. This sophisticated spyware, which we are tracking as PanDa, provides extensive surveillance to spy on the victim and collect sensitive data, including screen streaming, hidden virtual network computing (HVNC) and remote control capabilities, keylogging, screen lock capture and other actions to control settings of the infected device. At the heart of this operation is AppPanda, a centralized phishing management panel with additional services to drive infections delivered through malicious ads.
Netflix-themed malvertising drives victims to PanDa
We first observed the PanDa-associated phishing campaign in May 2026, spreading through Meta Ads with lures for Spanish-speaking users in Mexico to download and install a malicious application masquerading as the Netflix application. The downloaded Android package kit (APK) file, which we track as ShellA, serves as a loader for PanDa. In July, we observed the actors shift tactics, launching campaigns impersonating NovaFlix and a growing list of fictitious streaming brands to deliver PanDa. In August, we observed a new campaign wave impersonating Netflix and other legitimate streaming services, with the actors introducing the Facebook Pixel SDK into malvertising campaigns to improve ad-attribution tracking.
AppPanda: a window into a large scale phishing operation
During analysis of one of the landing pages, a tracking request URL led to the discovery of an unauthenticated centralized phishing management panel — branded AppPanda — which provided a window into the scale of the operation and malvertising campaigns. Over a one-week campaign beginning on July 2, 2026, the panel logged more than 350,000 landing page visits, 200,000 unique visitors and nearly 15,000 malicious app downloads across at least 22 phishing domains registered. The presence of the Chinese language throughout the panel suggests the phishing infrastructure was developed or maintained by Chinese-speaking threat actors.

Figure 1: The image depicts a screenshot of the phishing management panel dashboard July 7, 2026.
We discovered several other services and tooling surrounding AppPanda that enable individual operators to run their own Facebook ad campaigns that direct victims to phishing pages while relying on the centrally managed AppPanda panel for landing page configuration, campaign statistics and automated domain registration — an as-a-service model that lowers the barrier to entry for new affiliates. Data from the AppPanda dashboard image above shows a list of 11 configured landing page templates with campaign attributes, such as:
- Phishing page title and theme.
- Domain name hosting the phishing website.
- Malicious APK payload downloaded from the phishing website.
Other associated AppPanda tools and services we discovered include:
- APK Factory – A payload builder service allowing operators to generate fresh malicious APK builds from templates, supporting two malware families: the PanDa RAT and the previously reported BTMOB banking trojan.
- BAT1688 – An automated repacking and crypting platform that continuously obfuscates and re-signs APK payloads on a rotating schedule every 60 minutes to evade static detection.
- Appchi (Pixel Center) – A standalone web application branded as Pixel Center. Individual operators use this to manage Facebook ad campaigns, generate attribution links (PromoLinks), and track ad spend through a virtual payment service called HuiTongCard.
- Distribution jump domains – Employed disposable “jump domains”, which are embedded in ads on social media, to lead victims to phishing landing pages and shield the core infrastructure from takedowns.
Bypassing Google Play, targeting banks
Our analysis of the APK file downloaded from the phishing website revealed it was attributed to the Android loader we track as ShellA. The actors employed numerous tricks to ensure victims install PanDa payload. Upon launch of the loader application, the user is asked to toggle system settings to enable installs outside of the official Google Play store — allegedly to enjoy smooth playback in the fake Netflix app. The message displayed, screen layout and theme were meticulously tailored to the phishing campaign, which most likely resulted in high infection rates. In the background, the malware decrypts hidden files bundled inside itself and reassembles them into a working APK. Before installing, it randomizes part of that APK's signature so every install produces a unique file, defeating simple blocklist/hash-based detection. Just before the final APK is installed, the malware checks that "install from unknown sources" permission has already been granted on the device. Once payload installation is complete, the Android RAT executes and requests accessibility services permission. This permission enables the malicious app to steal secrets the user enters into login pages such as banking apps. Once privileges are granted, the application shows a loading page while the malicious payload initializes in the background.

Figure 2: The image depicts a screenshot of the installation process of the Android RAT mimicking the Netflix application May 14, 2026.
Further analysis revealed the malware communicating with the command-and-control (C2) server over a WebSocket connection with no encryption layer. We intercepted a list of applications targeted with the keylogging module, which abuses Android accessibility services to steal the secrets entered by victims. Targeted applications consisted of 62 banks and financial institutions across Mexico and Nigeria. For some targeted applications, the threat actors defined the application name exclusively, whereas the malware would dynamically retrieve the package name by the application name if the targeted app was installed on the infected device. The list of targeted banking applications is available in the full report below.
Campaign evolves: new domains, improved ad targeting
Through July 2026, Intel 471 researchers observed a notable collection of fresh phishing domains the threat actors registered. In contrast to the NovaFlix campaign in which a large number of websites impersonated the same brand, the phishing websites in the new campaign were configured with slightly different layouts, with actors creating fictitious streaming brands to impersonate legitimate streaming services, such as:
- AlvoPlay
- CeloloPlay
- CineviaBox
- EvotiPrime
- FaroreLive
- HalogoBox
- HalonaNow
- NovaoraPrime
- PicomiPlay
- RivasaTV
- UltraTV
- VivaPlay

Figure 3: The image depicts screenshots of phishing websites impersonating different streaming brands July 13, 2026.
The phishing campaigns remained active to continue to target Spanish-speaking users while the actors kept improving and expanding their infrastructure. In mid August 2026, Intel 471 researchers observed another campaign wave impersonating Netflix and PicomiPlay streaming services. The actors used the PromoLink attribution identifier, embedded in the Facebook advertisement links and Facebook Click Identifier to resolve the APK payload URLs. However, the actors by then had included Facebook Pixel SDK to track which ads resulted in the most downloads to improve infection rate in further campaigns. Apart from that, the Pixel Lead event is sent to Meta ads delivery systems to find more users likely to visit the website, so the operators let Meta’s machine learning algorithms provide optimized traffic. Download the full report to view a list of all jump domains and landing page domains.
Defend Against AppPanda and PanDa with Intel 471
The analyzed campaigns demonstrate a highly scalable, cost-effective phishing operation run by Chinese-speaking threat actors. Automated domain registration, landing page customization and rapid infrastructure deployment allowed the operation to reach substantial scale, with nearly 15,000 malicious APK downloads in a single week. The ShellA loader delivered a sophisticated Android RAT capable of screen streaming, HVNC, remote control and keylogging. Based on these findings, Intel 471 researchers anticipate future campaigns expanding into additional geographic regions and adopting new phishing page themes tailored to local audiences.
This campaign also illustrates a brand impersonation problem at scale. PanDa's targeting list of 62 banks and financial institutions, combined with its credential-harvesting capabilities, makes it a direct threat to mobile banking customers. For threats like this, correlating live C2 traffic, infrastructure pivots and newly registered phishing domains can help banks detect compromised devices earlier, potentially before stolen credentials are used for fraud.
Intel 471 Malware Intelligence tracks external C2 telemetry across evolving threat ecosystems like AppPanda, giving organizations a proactive edge against RAT-driven compromise. Our Malware intelligence tracking translates into additional defensive action:
- Enterprise defenders can use Retroactive Threat Detection on Verity471 to instantly generate tool-specific detection queries from this malware campaign report to check for the presence of this threat in historical logs.
- The Intel 471 Brand Exposure module surfaces early indicators of brand impersonation and abuse from phishing sites, social platforms, code repositories, app stores and the cyber underground, resulting in prioritized findings enriched with raw data and connections to Intel 471's trusted CTI reporting.
The full malware campaign analysis report including indicators is available for download here.
