Elastic Security Labs Tracks REF9334 KREMLIN Banking Malware

Moyen · The Hacker News ·

En bref

  • Elastic Security Labs tracks the activity as REF9334.
  • KREMLIN has been active since at least May 2025.
  • Lures impersonate about a dozen Brazilian banks.
  • The payload is a malicious Chrome and Edge browser extension.
  • No CVE is involved; user action and browser extension controls are central.

Researchers have detailed a Brazilian banking malware operation that distributes a toolkit named KREMLIN. Elastic Security Labs tracks the activity as REF9334. The campaign has been active since at least May 2025, according to the report, and uses fake pages that mimic about a dozen Brazilian banks. No CVE is tied to the activity.

The reported payload is a malicious browser extension for Google Chrome and Microsoft Edge. Once installed, it is described as capable of stealing credentials and session tokens. That combination matters because stolen session cookies can let an attacker reuse an authenticated session even when passwords are not known, and browser extensions can sit inside the user's normal browsing context.

The primary targets appear to be users of Brazilian banking services, not K-12 school systems in New Brunswick. Even so, the tradecraft is relevant to any organization with Chrome or Edge users. Browser extension abuse, credential phishing, and session-token theft are cross-industry problems, and staff who use personal banking or webmail on managed devices can blur the boundary.

Because there is no software vulnerability to patch, defenses depend on blocking known infrastructure, controlling extension installation, and detecting suspicious browser behavior. IT teams should treat vendor indicators as time-sensitive and verify them against Elastic Security Labs' published research before deploying blocks.

What to watch: new lure domains, extension IDs, or installer files; user reports of unexpected bank-branded pages; and browser alerts about newly added extensions. If compromise is suspected, revoke active sessions and reset credentials rather than only changing passwords.

À faire maintenant

  1. Pull the latest Elastic Security Labs report and block all listed domains, URLs, and extension IDs at the proxy, DNS, and browser policy layers.
  2. Enforce Chrome and Edge extension allowlisting through enterprise policy so users cannot install unapproved extensions.
  3. Review browser and endpoint logs for unexpected extension installs, especially on finance, HR, and executive devices.
  4. Alert users to fake Brazilian bank pages and instruct them not to install browser add-ons prompted by banking sites.
  5. For any suspected compromise, revoke active sessions and refresh tokens, then force password resets and re-enrollment of MFA.
  6. Monitor for new lure domains and extension identifiers, and update detections as vendor indicators change.
  7. Consider isolating affected endpoints and collecting browser artifacts for incident response.

Source originale

The Hacker News

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber