The extension you never installed: KREMLIN forges Chrome’s own integrity checks to steal banking sessions

The extension you never installed: KREMLIN forges Chrome’s own integrity checks to steal banking sessions
Elastic Security Labs tracked REF9334, a Brazilian banking malware operation using the KREMLIN toolkit to deliver malicious browser extensions, credential theft, and staged loaders through JavaScript, Node.js, RunPE, and Ethereum-based infrastructure. The campaign targeted Brazilian banking users and financial institutions, and Threat Command temporarily disrupted more than 1,500 infections by registering the network canary domain used by the malware. #REF9334 #KREMLIN #ThreatCommand #Ethereum #SentinelOne

Keypoints

  • KREMLIN is a multi-stage malware ecosystem used by REF9334 to install malicious browser extensions and steal browser data, credentials, and session tokens.
  • The infection chain uses JavaScript loaders, custom C++ installers, Node.js execution, and in some campaigns RunPE and DonutLoader.
  • The operators used Ethereum smart contracts as dead-drop resolvers to dynamically provide C2 endpoints and payload locations.
  • The malware bypasses Chromium integrity protections by modifying Secure Preferences and regenerating HMACs and encrypted hashes.
  • The main extension masquerades as legitimate software and supports screenshot theft, cookie theft, history collection, HTML injection, redirection, and request interception.
  • Campaign artifacts, Portuguese-language lures, and transaction timing indicate a focus on Brazilian users and banking institutions.
  • Threat Command registered the canary domain and observed over 1,500 infected systems attempting to contact it, mostly from Brazil.

MITRE Techniques

  • [T1059.007 ] JavaScript – The initial lure is a JavaScript file that the user manually executes to start the infection chain (‘the user manually executes’).
  • [T1497.001 ] Virtualization/Sandbox Evasion: System Checks – The loader checks for sandboxes and aborts if the host looks artificial (‘If there are fewer than five files or fewer than 50 processes, the malware assumes it is running in a sandbox and aborts execution’).
  • [T1105 ] Ingress Tool Transfer – The malware downloads additional stages, Node.js, binaries, and payloads from attacker infrastructure (‘downloads and installs malicious binaries from several sources’).
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Persistence is established with a scheduled task that launches the malware at logon (‘registered as MicrosoftNodeRuntimeUpdater’).
  • [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder? – The browser extension is installed directly into Chromium profile directories and activated through Secure Preferences changes (‘manually copies the extension into the browser’s profile directories and registers it in the Secure Preferences file’).
  • [T1620 ] Reflective Code Loading – RunPE and manual mapping are used to execute payloads in memory (‘loads it as a .NET assembly’ and ‘manual mapping and calling its entrypoint’).
  • [T1027 ] Obfuscated Files or Information – The loader and some strings are obfuscated/encrypted (‘strings are retrieved from a lookup table’ and ‘encrypts only some of its strings’).
  • [T1014 ] Rootkit? – Not applicable; omitted because not clearly supported in the article.
  • [T1057 ] Process Discovery – The malware enumerates running processes to detect analysis tools and sandbox software (‘searches it for process names associated with sandboxing software and security analysis tools’).
  • [T1497.002 ] User Activity Based Checks – It waits for browser inactivity before modifying profile files (‘waits until the browser is closed or the user has been inactive for at least two minutes’).
  • [T1005 ] Data from Local System – The extension collects browser databases, cookies, history, storage, and page source (‘Login Data’, ‘Cookies’, ‘Web Data’, ‘history’, ‘page source’).
  • [T1056.001 ] Keylogging – The extension registers input listeners to capture text entered into fields (‘Whenever the user modifies one of these fields… the extension sends the captured data to the server’).
  • [T1074.001 ] Local Data Staging: Local Data Staging – Collected data is compressed into ZIP archives before exfiltration (‘adds the following files and directories to a ZIP archive’).
  • [T1041 ] Exfiltration Over C2 Channel – Stolen data is sent to C2 endpoints over HTTPS/WebSocket (‘The encrypted ZIP archive… are sent to the following two C2 endpoints’).
  • [T1113 ] Screen Capture – The extension captures screenshots and uploads them (‘Captures the selected or active tab then uploads the compressed image’).
  • [T1204.002 ] User Execution: Malicious File – The victim is tricked into opening a lure document or script (‘masquerading as a banking, invoice, or company document, which the user manually executes’).
  • [T1114.001 ] Email Collection? – Not supported in the article; omitted.
  • [T1106 ] Native API – The malware uses Windows APIs such as ZwQuerySystemInformation, ReadProcessMemory, and CryptUnprotectData (‘uses ZwQuerySystemInformation’ and ‘passes the remaining blob to CryptUnprotectData’).

Indicators of Compromise

  • [File hash ] loader / binary / extension samples – 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42, c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268, and 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca
  • [Domain ] C2 / payload hosting – connection.upgradeonline[.]site, volmira[.]site, zaviro[.]online, codecaudiog[.]site, codecvideowin[.]online, acrobat-updater[.]com
  • [Domain ] Ethereum / dynamic config / worker endpoints – graph.checkeligibitily.workers[.]dev, version.checkeligibitily.workers[.]dev, orange-sun-195a.checkeligibitily.workers[.]dev
  • [Domain ] network canary / canary check – www.creamp1eonlyfans[.]net, creamp1eonlyfans[.]net
  • [URL path ] loader and exfiltration endpoints – /api/log_loader?hash=, /api/savecreds, /api/v1/fingerprint, /google_ws/, /google_api/81d47cb6.css
  • [Ethereum address ] smart contract config – 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b, 0x902EDbFECFF38f285Bf26283fB9cEB3700061873
  • [Customer ID ] campaign tracking – 98d8049e-804f-11f1-b79f-ae3a8bb85d01, 48502c50-a504-4811-aab8-ba978aeae237
  • [File name ] malicious components and lure artifacts – popup_{date}_{random}.js, SentinelMemoryScanner.exe, SentinelAgentCore.dll, items.json, manifest.json
  • [Extension ID ] malicious browser extensions – ndpbidppejfanjbhfgjlohfanbfbklff, djodclnjknbpambeaaapadmdfhmbpeog, cdgcjghdeinagopbaobhmaefigoafaaa


Read more: https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware