SlowMist|Sep 16, 2026 10:07
🚨 SlowMist TI Alert: KREMLIN Malware 🚨
Recently, a Brazilian banking malware operation, #REF9334, active since at least May 2025, was disclosed.
🔴 The #KREMLIN malware ecosystem uses multi-stage loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data.
⚠️ Its malicious extensions can be installed in #Chrome and #Edge without user approval by bypassing Chromium integrity mechanisms, including Secure Preferences, HMACs, and App-Bound encrypted hashes.
⛓️ The operation also uses #Ethereum smart contracts as dead-drop resolvers to dynamically update C2 endpoints and payload hosting locations, making the infrastructure harder to disrupt.
⚙️ After registering a network canary (kill switch) domain, analysts observed 1,515 infected hosts checking in, with 98.75% located in Brazil.
🛡️ Security teams should monitor for related malware, browser-extension activity, and infrastructure associated with the campaign.
🔑 Admin:
- 0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6
📜 Smart Contracts:
- 0x902EDbFECFF38f285Bf26283fB9cEB3700061873
- 0x64Def0A6099c4DE9C413B108EAae85A3C7457615
- 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b (currently active)
🔎 IOCs: https://github.com/elastic/labs-releases/tree/main/indicators/kremlin
📌 Source: https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware
Share To
HotFlash
APP
X
Telegram
CopyLink