Elastic Security Labs has identified a sophisticated Brazilian banking malware operation dubbed KREMLIN. Active for over 15 months, the malware targets customers of numerous Brazilian financial institutions through lures written in Portuguese. The operation stands out for its technical complexity, employing multi-stage JavaScript loaders, custom C++ installers, and the use of Ethereum smart contracts as dead-drop resolvers to dynamically update command-and-control (C2) infrastructure.
A core feature of KREMLIN is its ability to install a malicious browser extension in Chrome and Edge by bypassing Chromium's built-in integrity mechanisms. By manipulating Secure Preferences and regenerating required HMACs and App-Bound encrypted hashes, the malware forces the browser to load the extension as if it were a legitimate, user-approved installation. This allows the attackers to steal credentials, session tokens, and intercepted web requests directly from the victim's browser.
Researchers successfully disrupted over 1,500 active infections by registering a network canary domain used by the malware for sandbox detection. When the domain returned a response, the malware would assume it was in an analysis environment and terminate. Transaction analysis of the associated Ethereum wallet suggests the operators are based in the São Paulo time zone, further reinforcing the Brazilian attribution.
Top comments (0)