BlackStink is a browser-based banking malware campaign targeting financial institutions in Latin America. It is distributed as a malicious Google Chrome extension, including one observed using the name “G Docs – Servicio de almacenamiento de documentos en la nube” to mimic Google Docs. According to the provided reporting, the malware uses advanced WebInject techniques to take remote control of victims’ banking sessions in real time, bypass traditional detection mechanisms, steal credentials, and initiate unauthorized or fraudulent transfers directly within the browser. The campaign does not rely on traditional executable files, instead operating through the malicious browser extension. High-confidence indicators and traits mentioned in the content include the Chrome-extension delivery mechanism, the fake Google Docs-themed extension name, targeting of Latin American banks and financial institutions, credential theft, real-time session hijacking, and fraudulent transfer activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BlackStink is a malicious Chrome extension that targets banking portals in Latin America. It operates inside the browser, bypassing traditional endpoint security, to steal credentials and perform unauthorized financial transactions. It uses advanced techniques such as form cloning, event hijacking, and API-based fund transfers, all while maintaining persistence through background service workers and typosquatted C2 domains.
Chrome extension malware that targets Latin American banks, capable of credential theft, session hijacking, and real-time fraudulent transactions by injecting overlays and simulating user actions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.