KREMLIN Malware Forges Chrome Integrity Checks to Hijack Brazilian Banking Sessions
Elastic Security Labs has tracked a high-severity malware campaign called KREMLIN across seven operations over 15 months, targeting banking users in Brazil. The attack begins when a user opens a JavaScript file disguised as a bank receipt or invoice, which then silently downloads Node.js and establishes persistence via a scheduled task. KREMLIN uses Ethereum smart contracts as dead-drop resolvers to retrieve payloads and locate malicious browser extensions, which are injected into Chrome or Edge profiles without user consent by forging Chromium's Secure Preferences integrity checks. Once installed, the AVSync extension harvests cookies, session data, keystrokes, and HTTP traffic, and receives attacker commands over WebSocket. At the time of reporting, researchers had identified at least 1,515 infected endpoints, with blocking initial JavaScript execution identified as the most effective prevention measure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in