BoletimSec•September 17, 2026•🇵🇹Translated from Portuguese

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens in Brazil

Researchers from Elastic Security Labs have detailed the operation of a banking malware named KREMLIN, tracked under the identifier REF9334, that hijacks Chrome and Edge browsers to steal credentials and session tokens. The campaign targets Brazil almost exclusively.

Of the 1,515 infected systems identified, 98 percent are located in the country. The malware impersonates approximately ten different Brazilian banks. Infection starts with multi-stage JavaScript loaders disguised as banking documents, invoices, or corporate papers. Victims must execute the file manually, after which C++ installers and malicious browser extensions are downloaded.

To install the extension without triggering browser protections, the malware alters the Secure Preferences file, enables developer mode, and rewrites protection objects with forged metadata. Researchers refer to this method as Phantom Extension.

Once the extension is active, theft extends beyond passwords. The malware collects session tokens, cookies, data from sessionStorage and localStorage, browsing history from the previous 15 days, screenshots, information on open tabs, and the complete HTML of visited pages.

The operation has been active since May 2025 and includes seven distinct campaigns since June of that year. On 19 May 2026 the operators began using smart contracts on the Ethereum network as part of their infrastructure.

Recommendations include monitoring for unauthorized extension installations in corporate browsers and tracking changes to Chrome and Edge integrity files, as metadata replacement is central to the Phantom Extension technique.

Related articles

Securitylab•Malware & Botnets

How Malware Evades Sandboxes: Detection Techniques and Defense Strategies

Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.

BoletimSec•Malware & Botnets

Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers

Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.

BoletimSec•Malware & Botnets

Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware

Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.

AntiMalware•Malware & Botnets

SC Malware on WordPress Restores Deleted Backdoors in Seconds via Eight Persistence Points

Researchers at Sucuri have analyzed the SC malware targeting WordPress sites, which rapidly restores any removed backdoor components through a minimum of eight interconnected persistence mechanisms. The infection hides across PHP configuration settings, hidden loaders, theme files, and plugins, with some elements executing before standard WordPress plugins load. Copies of the malicious code are also stored in the database and System V shared memory on supported servers, allowing full reinfection from surviving sources after file cleanup. The backdoor evades plugin listings, gathers site and administrator session data, deploys additional PHP code, and disables security plugins while injecting JavaScript for payment data theft in online stores. Command-and-control occurs through public Ethereum RPC gateways and smart contracts with multiple fallback channels. Sucuri warns that PHP caching of the loader directive can crash request handling if the referenced file is deleted without prior preparation, and recommends a sequenced cleanup process.