吴说区块链|Sep 16, 2026 10:38
According to WuTalk, SlowMist has issued a security alert stating that the Brazilian banking trojan operation REF9334, active since at least May 2025, utilizes the KREMLIN malware ecosystem with multi-stage loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data. It can bypass Chromium integrity mechanisms to install Chrome and Edge extensions without user consent. The operation also leverages Ethereum smart contracts as a 'dead letter parser' to dynamically update C2 endpoints and payload hosting locations. Analysts discovered that after setting up a network Canary domain, a total of 1,515 infected hosts reconnected, with 98.75% located in Brazil.
https://(wublock123.com)/news/slowmist-kremlin-malware-uses-ethereum-smart-contracts-to-update-infrastructure-68486
Share To
HotFlash
APP
X
Telegram
CopyLink