Intel 471

Inside AppPanda: A Sprawling Phishing Operation Targeting Android Users in Mexico

In July 2026, Intel 471 researchers uncovered a sprawling phishing operation run by Chinese-speaking threat actors that used fake movie streaming apps to trick Spanish-speaking victims across Mexico into installing an Android remote access trojan (RAT) tool on their phones. The spyware, dubbed PanDa, features screen streaming, silent remote control, keylogging, screen-lock capture and other capabilities to control device settings.

Victims were funneled toward PanDa through paid Meta advertisements impersonating Netflix, NovaFlix and a growing roster of invented streaming brands. Behind the scenes, an exposed, unauthenticated management panel branded AppPanda revealed the true scale of the operation, and just how far the as-a-service model has lowered the barrier to entry for new affiliates.

In this report, you'll learn about:

  • How fake streaming apps and Meta ad campaigns funneled victims to the ShellA loader, which installed PanDa in the background
  • AppPanda, the centralized management panel that logged more than 350,000 landing page visits and nearly 15,000 malicious app downloads in a single week
  • How individual operators run their own ad campaigns while plugging into centrally managed phishing pages, domain registration and payload delivery
  • BAT1688, the automated repacking and crypting platform that regenerates malicious APK builds every 60 minutes to defeat antivirus detection
  • The keylogging target list covering 62 banks and financial institutions across Mexico and Nigeria, and what it may reveal about the actors behind the campaign

Download Intel 471's report Inside AppPanda: A Sprawling Phishing Operation Targeting Android Users in Mexico to get our full breakdown of the infrastructure, malware and tooling behind this evolving threat.

Loading form...