Facebook Ads Promote Fake Streaming Apps Delivering PanDa RAT

Facebook Ads Promote Fake Streaming Apps Delivering PanDa RAT

Intel 471 says Chinese-speaking operators used fake streaming apps and Facebook ads to infect Android users with the PanDa RAT (remote access trojan).

Listen to this article

0:00

Press play to start listening

Cybersecurity firm Intel 471 has identified a malware campaign in which Chinese-speaking threat actors used fake streaming services to target Spanish-speaking Android users in Mexico with PanDa RAT, a newly identified Android RAT.

The findings, shared with Hackread.com, show an operation that combines social media advertising, phishing websites and several tools for delivering Android malware. The campaign was first spotted in May 2026, when the attackers advertised a fake Netflix application.

By July 2026, the attackers were also using NovaFlix and several fictitious streaming brands, including AlvoPlay, CeloloPlay, CineviaBox, EvotiPrime, PicomiPlay and UltraTV to spread the malware.

Facebook Ads Promote Fake Streaming Apps Delivering PanDa RAT
Screenshot showing a fake Netflix app used to install the PanDa RAT (Credit: Intel 471)

From a Fake App to PanDa RAT

The attack starts with an advertisement that sends users to a streaming-themed website offering to download an Android APK. It appears to be a legitimate entertainment app but is actually a loader that Intel 471 calls ShellA. When launched, it asks the user to change an Android setting, claiming this is needed for playback. The change actually permits installation from outside Google Play.

Once the fake app is opened, ShellA decrypts files hidden inside it and rebuilds them into a second APK. Before installing the new package, the loader randomises part of its signature, giving each copy a different file hash and making hash-based blocking less reliable.

After PanDa reaches the phone, it asks for Accessibility Services access, a permission that allows it to watch and control activity on the device. The RAT can stream the screen, control the phone remotely, log keystrokes, and collect screen-lock information. Its keylogger can also steal information entered into selected applications.

Much of that monitoring was aimed at financial applications. Intel 471 found a keylogging target list covering 62 banks and other financial institutions in Mexico and Nigeria. The researchers said the unusual combination may mean that different affiliates are using the same malware, although they could not confirm that explanation.

Intel 471 also found that PanDa communicated with its command-and-control server through an unencrypted WebSocket connection.

Fake streaming apps have been used in Android attacks before. As Hackread.com reported in 2021, a fake Netflix app called FlixOnline was discovered that could monitor WhatsApp notifications and automatically send malicious replies to a victim’s contacts.

Facebook advertisements promoting fake streaming apps used to deliver the PanDa RAT (Credit: Intel 471)

A Larger Operation Behind the Apps

According to Intel 471’s report, researchers learned more about the operation after finding an exposed AppPanda management panel that required no authentication. During the week beginning July 2, 2026, the panel recorded more than 350,000 landing-page visits, 200,000 unique visitors, and nearly 15,000 malicious APK downloads across at least 22 phishing domains.

The operation also had several supporting services. APK Factory could generate new malicious APKs from templates for PanDa and BTMOB. BAT1688 repeatedly repackaged and obfuscated APKs, with new builds produced every 60 minutes to make static detection harder. Appchi, also known as Pixel Center, helped operators manage Facebook advertising, generate tracking links, and monitor spending.

Intel 471 observed another campaign in mid-August using Netflix and PicomiPlay themes. The operators continued changing domains and added the Facebook Pixel SDK to measure which advertisements generated downloads and improve future campaigns.

Intel 471 expects the operators to target other regions with brands adapted to local audiences. Android users should avoid APKs promoted through social media advertisements and reject requests from streaming apps to allow installations from unknown sources or grant Accessibility Services access.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts