Elastic Security Labs tracked REF9334, a Brazilian banking malware operation using the KREMLIN toolkit to deliver malicious browser extensions, credential theft, and staged loaders through JavaScript, Node.js, RunPE, and Ethereum-based infrastructure. The campaign targeted Brazilian banking users and financial institutions, and Threat Command temporarily disrupted more than 1,500 infections by registering the network canary domain used by the malware. #REF9334 #KREMLIN #ThreatCommand #Ethereum #SentinelOne
Keypoints
- KREMLIN is a multi-stage malware ecosystem used by REF9334 to install malicious browser extensions and steal browser data, credentials, and session tokens.
- The infection chain uses JavaScript loaders, custom C++ installers, Node.js execution, and in some campaigns RunPE and DonutLoader.
- The operators used Ethereum smart contracts as dead-drop resolvers to dynamically provide C2 endpoints and payload locations.
- The malware bypasses Chromium integrity protections by modifying Secure Preferences and regenerating HMACs and encrypted hashes.
- The main extension masquerades as legitimate software and supports screenshot theft, cookie theft, history collection, HTML injection, redirection, and request interception.
- Campaign artifacts, Portuguese-language lures, and transaction timing indicate a focus on Brazilian users and banking institutions.
- Threat Command registered the canary domain and observed over 1,500 infected systems attempting to contact it, mostly from Brazil.
MITRE Techniques
- [T1059.007 ] JavaScript â The initial lure is a JavaScript file that the user manually executes to start the infection chain (âthe user manually executesâ).
- [T1497.001 ] Virtualization/Sandbox Evasion: System Checks â The loader checks for sandboxes and aborts if the host looks artificial (âIf there are fewer than five files or fewer than 50 processes, the malware assumes it is running in a sandbox and aborts executionâ).
- [T1105 ] Ingress Tool Transfer â The malware downloads additional stages, Node.js, binaries, and payloads from attacker infrastructure (âdownloads and installs malicious binaries from several sourcesâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Persistence is established with a scheduled task that launches the malware at logon (âregistered as MicrosoftNodeRuntimeUpdaterâ).
- [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder? â The browser extension is installed directly into Chromium profile directories and activated through Secure Preferences changes (âmanually copies the extension into the browserâs profile directories and registers it in the Secure Preferences fileâ).
- [T1620 ] Reflective Code Loading â RunPE and manual mapping are used to execute payloads in memory (âloads it as a .NET assemblyâ and âmanual mapping and calling its entrypointâ).
- [T1027 ] Obfuscated Files or Information â The loader and some strings are obfuscated/encrypted (âstrings are retrieved from a lookup tableâ and âencrypts only some of its stringsâ).
- [T1014 ] Rootkit? â Not applicable; omitted because not clearly supported in the article.
- [T1057 ] Process Discovery â The malware enumerates running processes to detect analysis tools and sandbox software (âsearches it for process names associated with sandboxing software and security analysis toolsâ).
- [T1497.002 ] User Activity Based Checks â It waits for browser inactivity before modifying profile files (âwaits until the browser is closed or the user has been inactive for at least two minutesâ).
- [T1005 ] Data from Local System â The extension collects browser databases, cookies, history, storage, and page source (âLogin Dataâ, âCookiesâ, âWeb Dataâ, âhistoryâ, âpage sourceâ).
- [T1056.001 ] Keylogging â The extension registers input listeners to capture text entered into fields (âWhenever the user modifies one of these fields⌠the extension sends the captured data to the serverâ).
- [T1074.001 ] Local Data Staging: Local Data Staging â Collected data is compressed into ZIP archives before exfiltration (âadds the following files and directories to a ZIP archiveâ).
- [T1041 ] Exfiltration Over C2 Channel â Stolen data is sent to C2 endpoints over HTTPS/WebSocket (âThe encrypted ZIP archive⌠are sent to the following two C2 endpointsâ).
- [T1113 ] Screen Capture â The extension captures screenshots and uploads them (âCaptures the selected or active tab then uploads the compressed imageâ).
- [T1204.002 ] User Execution: Malicious File â The victim is tricked into opening a lure document or script (âmasquerading as a banking, invoice, or company document, which the user manually executesâ).
- [T1114.001 ] Email Collection? â Not supported in the article; omitted.
- [T1106 ] Native API â The malware uses Windows APIs such as ZwQuerySystemInformation, ReadProcessMemory, and CryptUnprotectData (âuses ZwQuerySystemInformationâ and âpasses the remaining blob to CryptUnprotectDataâ).
Indicators of Compromise
- [File hash ] loader / binary / extension samples â 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42, c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268, and 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca
- [Domain ] C2 / payload hosting â connection.upgradeonline[.]site, volmira[.]site, zaviro[.]online, codecaudiog[.]site, codecvideowin[.]online, acrobat-updater[.]com
- [Domain ] Ethereum / dynamic config / worker endpoints â graph.checkeligibitily.workers[.]dev, version.checkeligibitily.workers[.]dev, orange-sun-195a.checkeligibitily.workers[.]dev
- [Domain ] network canary / canary check â www.creamp1eonlyfans[.]net, creamp1eonlyfans[.]net
- [URL path ] loader and exfiltration endpoints â /api/log_loader?hash=, /api/savecreds, /api/v1/fingerprint, /google_ws/, /google_api/81d47cb6.css
- [Ethereum address ] smart contract config â 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b, 0x902EDbFECFF38f285Bf26283fB9cEB3700061873
- [Customer ID ] campaign tracking â 98d8049e-804f-11f1-b79f-ae3a8bb85d01, 48502c50-a504-4811-aab8-ba978aeae237
- [File name ] malicious components and lure artifacts â popup_{date}_{random}.js, SentinelMemoryScanner.exe, SentinelAgentCore.dll, items.json, manifest.json
- [Extension ID ] malicious browser extensions â ndpbidppejfanjbhfgjlohfanbfbklff, djodclnjknbpambeaaapadmdfhmbpeog, cdgcjghdeinagopbaobhmaefigoafaaa