Koi Security linked three browser-extension campaigns—ShadyPanda, GhostPoster and Zoom Stealer—to an operator it calls DarkSpectre. A December 2025 report put their combined impact at more than 8.8 million users over more than seven years, but that reported aggregate should not be read as a verified count of unique people. A separate 2.2 million figure was reported for the newly described operation.
What is DarkSpectre?
DarkSpectre is the name Koi Security assigned to an operator it assessed as being behind three connected campaigns. The attribution and campaign links are researchers’ conclusions, as summarized in secondary reporting—not a publicly verified identity for a named person or organization. The Hacker News reported the findings on December 31, 2025: DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide.
The reported combined impact exceeded 8.8 million users across more than seven years. The newly described operation was separately attributed 2.2 million users. The reviewed reporting does not establish whether the figures count unique individuals, nor does it provide an independently published census or enough methodology to interpret them as confirmed victims. They should be treated as reported aggregate impact figures.
Which campaigns and browsers were involved?
The three campaigns named in reporting are ShadyPanda, GhostPoster and Zoom Stealer. CERT-EU’s January 2026 bulletin describes broader activity involving Chrome, Edge, Firefox and Opera: Cyber Brief 26-01. This does not mean every extension available for those browsers—or every person using them—was affected.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
The reviewed sources do not provide a verified, current list of implicated extension names or establish the status of any store listings. A browser brand alone is not enough to determine whether a particular installation was involved.
How did the reported campaigns work?
Tata Communications’ January 13, 2026 threat-intelligence advisory summarizes Koi Security’s descriptions of the tactics: Threat Intelligence Advisory, 13 January 2026.
- ShadyPanda: Some extensions could appear legitimate for years before malicious activation, according to the advisory’s account of Koi Security’s findings.
- GhostPoster: The campaign reportedly concealed JavaScript in image assets.
- Zoom Stealer: The operation reportedly collected corporate meeting intelligence.
CERT-EU characterized the reported effects as surveillance, fraud and corporate espionage. The sources reviewed do not quantify financial losses or confirm specific victims, so those harms should not be mistaken for a documented loss total or a list of verified organizations.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to review browser extensions
For personal browsers
- Open the browser’s extensions or add-ons page and review the extensions currently installed. The exact menu path differs by browser and version.
- Remove extensions you no longer use or cannot identify. If you are unsure whether an extension is required, check its publisher’s information before removing it.
- Before installing or retaining an extension, scrutinize its publisher, requested permissions and stated purpose. Be cautious when the permissions seem broader than the function requires.
- If you suspect an extension is involved, remove it and review accounts or devices that may have been exposed. The reviewed sources do not provide a campaign-specific cleanup list or verified remediation steps for individual users.
For organizations
- Maintain an inventory of browser extensions in use.
- Set an approval process or allowlist for extensions employees may install.
- Review requested permissions and business need when approving extensions, and revisit the inventory periodically.
These are general precautions that address extension risk; the available summaries do not establish a campaign-specific list of extensions to remove or show that an antivirus product alone resolves a browser-extension compromise.
Recommended Free Tools
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

