- Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025
- Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data
- 1,515 infections found, 98% in Brazil
Security researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser extensions to compromise users and steal sensitive information.
In an in-depth report published earlier this week, the researchers said the campaign has been active since at least May 2025. Dubbed REF9334, the campaign uses fake banking, invoice, and business documents, to trick victims into installing malware which, in turn, deploys a malicious extension in Chrome and Edge browsers.
The researchers named the malware “Kremlin”, and say it can steal browser credentials, cookies, session information, monitor browser activity, grab screenshots, and steal information from websites that the victims visit. But the goal of the campaign is primarily to target Brazilian bank users.
A thousand victims
The malware really makes an effort to hide and persist in the target environment. For example, it first checks to see if it’s in a sandbox and if so – it simply won’t run. If instead it determines that it’s running on a real user’s computer, it will deploy an extension with the name “AVSync System Inc.” in an attempt to trick the victim into thinking they have an antivirus addon running in the browser.
It also doesn’t use a fixed C2 server, but rather stores the information on the Ethereum blockchain, since it’s a lot harder to disrupt the communication between the operators and the infected machines that way.
During their investigation, Elastic researchers were able to take control of a domain that the malware used and discovered that it had infected 1,515 systems. Almost all of them (98%) were located in Brazil. They were also able to register the network canary domain and point it to their webhost, which resulted in the loader assuming it was in a sandbox. This also meant “the infections have not moved past the initial access”, Elastic explained.
The full list of indicators of compromise can be found on this link.
Via The Hacker News
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.
