SlowMist reported that REF9334, a Brazilian banking malware campaign active since at least May 2025, uses the KREMLIN malware ecosystem to steal credentials, session tokens, and sensitive data through multi-stage loaders and malicious browser extensions.
The extensions can bypass Chromium integrity mechanisms, including Secure Preferences, HMAC, and App-Bound encryption hashes, to install themselves in Chrome and Edge without user approval. The campaign also uses Ethereum smart contracts as a “dead drop resolver” to dynamically update C2 endpoints and payload hosting locations.
Analysts observed 1,515 infected hosts checking in after registering network Canary domains, with 98.75% located in Brazil. SlowMist advised security teams to monitor related malware, browser extension activity, and associated infrastructure.
KREMLIN Malware Uses Ethereum Contracts to Update Attack Infrastructure
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
