The record
Written from the 1 report below. Nothing here is unsourced.
- A Brazilian banking malware operation called KREMLIN tricks users into running fake banking or invoice documents that install malicious browser extensions.
- The malware targets Google Chrome and Microsoft Edge users and impersonates a dozen Brazilian banks to steal login credentials, session tokens, and other sensitive data.
- The operation uses Ethereum smart contracts to hide its command-and-control servers, making the infrastructure harder to take down.
- The malicious extension can take screenshots, steal cookies and browser storage, capture full page HTML, and intercept web requests.
- Users of Brazilian banking services should be cautious of unexpected document downloads, as stolen credentials and session tokens can give attackers direct access to bank accounts.
What to watch next
- Whether the domains volmira[.]site and zaviro[.]online and the C2 server are blocked or sinkholed
- Whether Google and Microsoft patch the Secure Preferences integrity bypass used by the extension
- Further updates on the scope of affected Brazilian banks and victims
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Cyril Francois
security
2 quotes · 1 outlet
“The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data”
In the article
…under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge. " The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data ," security researchers Cyril François and Andrew Pease said in a technical report shared with The Hacker News. "Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and…
“Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs, and App-Bound encrypted hashes.”
In the article
…C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data," security researchers Cyril François and Andrew Pease said in a technical report shared with The Hacker News. " Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs, and App-Bound encrypted hashes. " A defining aspect of the operation is the use of blockchain to conceal the threat actor-controlled infrastructure, leveraging Ethereum smart contracts as dead drop resolvers to dynamically update command-and-control…
Coverage1
All filed from India
Named Brazil · China · SentinelOne · Andrew Pease · APT31 · Cyril Francois · Elastic Security Labs · REF9334
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
