🚨 🇧🇷 the Brazilian campaign of banking malware REF9334, active since at least May 2025, was recently revealed. The KREMLIN malware ecosystem uses Ethereum smart contracts as dynamic resolvers to update command-and-control endpoints as well as the hosting locations of payloads. The malicious infrastructure also distributes browser extensions that steal credentials and session tokens by bypassing Chromium security mechanisms. Researchers observed 1,515 infected hosts connect following the campaign’s registration of a Canary domain, with 98.75% located in Brazil.
$ETH
$LSK
$ZEC
$ETH
$LSK
$ZEC