THREAT OPS › Threat News › The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
<p>Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, <code>Kr3mlin4rt1st</code>), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during Sã
Attributed threat actors
- MuddyWaterG0069
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- Windows Management InstrumentationT1047
- Screen CaptureT1113
- System Owner/User DiscoveryT1033
- Standard EncodingT1132.001
- Embedded PayloadsT1027.009
- Encrypted/Encoded FileT1027.013
- IP AddressesT1590.005
- JavaScriptT1059.007
- Steal Web Session CookieT1539
- Match Legitimate Resource Name or LocationT1036.005
- Masquerade File TypeT1036.008
- Malicious FileT1204.002
- Symmetric CryptographyT1573.001
- Browser ExtensionsT1176.001
- System ChecksT1497.001
- Automated CollectionT1119
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Scheduled Task/JobT1053
- Software ExtensionsT1176
- Native APIT1106
- Data from Local SystemT1005
- Deobfuscate/Decode Files or InformationT1140
- Upload MalwareT1608.001
- Credentials from Password StoresT1555
- Archive via LibraryT1560.002
- Social EngineeringT1684
- MasqueradingT1036
- Process InjectionT1055
- Reflective Code LoadingT1620
- Archive Collected DataT1560
- Browser Session HijackingT1185
- Credentials from Web BrowsersT1555.003
- Browser Information DiscoveryT1217
- Command and Scripting InterpreterT1059
- Indicator RemovalT1070
- File and Directory DiscoveryT1083
- Masquerade Task or ServiceT1036.004
- Virtualization/Sandbox EvasionT1497
- Web ServiceT1102
- Stage CapabilitiesT1608
- User ExecutionT1204
- Process DiscoveryT1057
- Exfiltration Over C2 ChannelT1041
- PowerShellT1059.001
- Data ObfuscationT1001
- Hijack Execution FlowT1574
- Obfuscated Files or InformationT1027
- Encrypted ChannelT1573
- Input CaptureT1056
- Social MediaT1593.001
- CredentialsT1589.001
- SteganographyT1027.003
- Protocol or Service ImpersonationT1001.003
- Web Session CookieT1550.004
- Security Software DiscoveryT1518.001
- Data EncodingT1132
- ImpersonationT1684.001
- File DeletionT1070.004
- Web ProtocolsT1071.001
- Software DiscoveryT1518
- Ingress Tool TransferT1105
- Dynamic API ResolutionT1027.007
- SteganographyT1001.002
- Dead Drop ResolverT1102.001
- Data from Local SystemAML.T0037
- Command and Scripting InterpreterAML.T0050
- ImpersonationAML.T0073
- MasqueradingAML.T0074
- Stage CapabilitiesAML.T0079
- Process DiscoveryAML.T0089
- Virtualization/Sandbox EvasionAML.T0097
Indicators of compromise
- 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42sha256
- 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552sha256
- c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268sha256
- 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7casha256
- ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5fsha256
- cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0sha256
- 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2csha256
- 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9sha256
- 5c92d3b8734b4f498752f735a1ca0987md5
- f9e95a1e1fa3f3aebfc802c6c8e6a2ebmd5
- 87b76a60ba7c474dbf8f689df2808e1amd5
- 5f109e7bb3df4dea81946f2f853da288md5
- 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07beth
- 0x902EDbFECFF38f285Bf26283fB9cEB3700061873eth
- 0x64Def0A6099c4DE9C413B108EAae85A3C7457615eth
- 0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6eth
- 0x8a711333899C173A1DC1a3523335e52Becce9A44eth
- 0x25a6a4fe0cc0f8ebf19836ad50fe104c3cbc9d6aeth
- 0x56eddb7aa87536c09ccc2793473599fd21a8b17feth
- 0xb2b7e8403b4534d43b477d4d4bd6f829437463c8eth
- 0xdd3d72c53ff982ff59853da71158bf1538b3ceeeeth
- 0x28c6c06298d514db089934071355e5743bf21d60eth
- 0x1AD4436893850Cc1dA180b2488e764bEB9E2A379eth
- 0x737A8DeA4Db63B3b24f19698AF9e5Bc6f08DE8EEeth
- 0x77e2d84e79D65CE84C2dB606E984380A88F4594feth
- 0x5b3f4643d012ad6caca0a392b1a54b142b59aba5eth
- 0xAC0a95225938E1D85C1E41e35495563eF733947aeth
- 0x81ffb6c5f72e934a79b46a867063bff5a7a222b1eth
- 0xd3d8d6b0e6d0f8dd3705247b54b8fe55f1c77567eth
- 0x7e27a030b8879cea5e92e3da650eba0098116908eth
- 0x8236a0bcf102db910df27190dccc57a75e9faa8beth
- 0x4f7D712D0B53fDf3c96896EB411467B30Da23406eth
- https://www.virustotal.com/gui/file/106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42url
- https://www.virustotal.com/gui/file/5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552url
- https://connection.upgradeonline.siteurl
- https://granderevolucao.store/5c92d3b8734b4f498752f735a1ca0987/{campaignId}url
- https://www.virustotal.com/gui/file/c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268/contenturl
- https://www.security.com/threat-intelligence/iran-seedworm-electronicsurl
- http://www.creamp1eonlyfans.neturl
- https://volmira.site/api/ext/versionurl