Researchers at Intel 471 have uncovered a phishing operation that used paid Facebook ads and counterfeit streaming apps to push an Android remote access trojan called PanDa onto phones in Mexico.

The targets are Spanish-speaking Android users, and researchers point to Chinese-speaking threat actors behind it. It surfaced in May 2026 with an app masquerading as Netflix, then moved on to NovaFlix and made-up brands like AlvoPlay, CineviaBox and UltraTV.
The delivery is what stands out. These apps weren’t buried on an obscure download site. They were advertised on Facebook.

How the Fake Streaming Apps Infect Android Devices
The ad leads to a streaming site offering an Android APK download. It looks like an entertainment app, but it’s a loader Intel 471 named ShellA.
On launch, it tells the user to flip an Android setting, claiming playback needs it. What that toggle really does is permit installs from outside Google Play.
The loader then rebuilds a second APK from files hidden inside itself, randomizing the signature so every copy carries a different file hash. Blocklists work by recognizing a known bad file, and a fresh hash on every install slips past that.

What PanDa Does Once It’s On Your Phone
The trojan then requests Accessibility Services permission, which Intel 471 says lets it steal whatever you type into login pages, banking apps included. PanDa also carries screen streaming, remote control and screen-lock capture.
Researchers intercepted a keylogging target list covering 62 banks and financial institutions across Mexico and Nigeria.
Hide Your Digital Fingerprint
Inside the AppPanda Operation
The scale showed up in a control panel branded AppPanda, left online with no password on it, shared infrastructure that individual operators run their own campaigns through.
In the single week beginning July 2, 2026, that panel logged more than 350,000 landing page visits from 200,000 unique visitors, plus nearly 15,000 malicious app downloads across at least 22 domains.
Behind it sit a payload builder, a service that re-signs those payloads every 60 minutes so the files never stop changing, and an ad tool tracking campaigns and spend. That is a marketing stack, aimed at getting malware onto more phones.
Why Cord-Cutters Should Pay Attention
Treat any APK promoted through a social media ad as suspect, and walk away from a video app that asks for Accessibility Services. Playing a movie does not require that permission.
Stick to sources you can trace to a real developer. Our list of vetted APKs and the streaming apps guide point to apps we’ve used, and files in the TROYPOINT Toolbox get checked first. A VirusTotal scan is still worth the minute.
Final Thoughts from Troy
The part that should bother people is the delivery. This ran as paid advertising for months, and it was a threat intelligence firm that pieced it together, not the platform serving the ads.
We’ve covered fake IPTV apps carrying banking malware before, but those spread through download sites and messaging channels. This one paid to land in the feed, and researchers expect it in other regions next.
For more details on this story, refer to the report from Hackread and the original report from Intel 471.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.




