A newly uncovered cybercrime toolkit known as “Panda Shop” is making waves out of China, arming threat actors with the ability to harvest sensitive financial credentials—ranging from Google Pay and Apple Pay accounts to credit card numbers.
This toolkit stands out by deploying highly persuasive mobile-optimized phishing sites, expertly mimicking familiar brands such as USPS, DHL, and leading banks. Through deceptive text messages, it exploits user trust and mobile browsing limitations to trick victims into handing over their financial data.

Panda Shop Smishing Toolkit Redefines Mobile Threat Landscape with Industrial-Scale Campaigns
A cutting-edge phishing toolkit, code-named Panda Shop, has emerged from China, showcasing a new level of maturity in mobile-based fraud operations. Instead of relying on generic tactics, this toolkit delivers meticulously tailored phishing pages built to seamlessly blend with mobile interfaces and browser environments. Victims, believing they’re interacting with trusted services like postal carriers or banks, are tricked into divulging sensitive financial details.
First detected by Resecurity on March 22, 2025, the platform’s operators claim the capability to distribute a staggering 2 million fraudulent messages per day. At that scale, the operation could theoretically target nearly 60 million individuals each month—roughly equivalent to the entire U.S. population, twice over.
Researchers believe Panda Shop may be a reengineered successor to the notorious Smishing Triad, given the structural and scripting similarities between the two. However, Panda Shop brings new refinements, including expanded device compatibility and enhanced delivery systems. The threat actors behind it have openly mocked international law enforcement, declaring they are beyond the reach of U.S. authorities due to their base of operations in China.
Modern Messaging Weaponized
What sets Panda Shop apart from traditional smishing kits is its exploitation of modern communication channels. Rather than depending on SMS alone, the platform primarily distributes lures via Google RCS and Apple iMessage—channels with more dynamic formatting and higher user trust.
This enables attackers to craft more engaging and believable messages, bypassing the limitations of SMS while tapping into enriched media capabilities and interactive elements. Combined with clever social engineering, the result is a higher success rate in data extraction.
Stealth and Sophistication
The kit’s operators also implement advanced counterintelligence measures. By abusing legitimate IP verification APIs—such as those from IP Registry Co.—they can screen incoming traffic to detect bots, researchers, or cybersecurity firms. This selective targeting ensures the phishing infrastructure remains hidden from most threat monitoring tools.
Once users are tricked into submitting their data, it’s immediately routed to the attackers—often in real time. The kit also supports harvesting OTPs (One-Time Passwords), giving threat actors the ability to sidestep multi-factor authentication protections. This mirrors tactics seen in high-end phishing services like EvilProxy, allowing attackers to hijack sessions even on protected accounts.

USPS-Themed Phishing Page Unmasks Technical Clues Behind ‘Panda Shop’ Operation
One phishing lure linked to Panda Shop mimics a USPS delivery notification page, complete with a polished interface prompting users to submit their credit card details—seamlessly engineered to deceive mobile users at a glance.
A deeper dive into leaked backend files revealed revealing breadcrumbs. Among them: a Shanghai time zone configuration and explicit mentions of NACOS—a service orchestration platform developed by Alibaba and widely used in China. These indicators further cement the operation’s origin within Chinese cybercriminal circles.
Investigators also traced the domain’s registration back to Beijing Lanhai Jiye Technology Co., Ltd., a domain registrar previously sanctioned by ICANN for egregious violations of registrar compliance, including failure to enforce anti-abuse measures.




