SlowMist
SlowMist|Sep 16, 2026 10:07
🚨 SlowMist TI Alert: KREMLIN Malware 🚨 Recently, a Brazilian banking malware operation, #REF9334, active since at least May 2025, was disclosed. 🔴 The #KREMLIN malware ecosystem uses multi-stage loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data. ⚠️ Its malicious extensions can be installed in #Chrome and #Edge without user approval by bypassing Chromium integrity mechanisms, including Secure Preferences, HMACs, and App-Bound encrypted hashes. ⛓️ The operation also uses #Ethereum smart contracts as dead-drop resolvers to dynamically update C2 endpoints and payload hosting locations, making the infrastructure harder to disrupt. ⚙️ After registering a network canary (kill switch) domain, analysts observed 1,515 infected hosts checking in, with 98.75% located in Brazil. 🛡️ Security teams should monitor for related malware, browser-extension activity, and infrastructure associated with the campaign. 🔑 Admin: - 0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6 📜 Smart Contracts: - 0x902EDbFECFF38f285Bf26283fB9cEB3700061873 - 0x64Def0A6099c4DE9C413B108EAae85A3C7457615 - 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b (currently active) 🔎 IOCs: https://github.com/elastic/labs-releases/tree/main/indicators/kremlin 📌 Source: https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware
Share To

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads