SlowMist reported that REF9334, a Brazilian banking malware campaign active since at least May 2025, uses the KREMLIN malware ecosystem to steal credentials, session tokens, and sensitive data through multi-stage loaders and malicious browser extensions. The extensions can bypass Chromium integrity mechanisms, including Secure Preferences, HMAC, and App-Bound encryption hashes, to install themselves in Chrome and Edge without user approval. The campaign also uses Ethereum smart contracts as a “dead drop resolver” to dynamically update C2 endpoints and payload hosting locations. Analysts observed 1,515 infected hosts checking in after registering network Canary domains, with 98.75% located in Brazil. SlowMist advised security teams to monitor related malware, browser extension activity, and associated infrastructure.