Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Elastic Security Labs describes REF9334 as a Brazilian banking-malware operation active since May 2025. The toolkit is named KREMLIN by its author, Kr3mlin4rt1st, and deploys a malicious Chromium extension while using Node.js, scheduled-task persistence, DLL sideloading, and Ethereum smart contracts for configuration and payload delivery.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Étape 1 : Évasion sandbox (comptage de fichiers bureau, processus WMI).
Les fichiers JavaScript utilisent des noms en portugais; l’infection débute par un fichier JavaScript.
TTPs détectés : T1027.007 — Obfuscated Files or Information: Dynamic API Resolution.
TTPs détectés : T1027.009 — Obfuscated Files or Information: Embedded Payloads.
TTPs détectés : T1027.013 — Obfuscated Files or Information: Encrypted/Encoded File.
The starting point of KREMLIN is a JavaScript file that masquerades as a banking, invoice, or company document and is manually executed by the victim.
Persistance via tâche planifiée (MicrosoftNodeRuntimeUpdater).
DLL sideloading de SentinelMemoryScanner.exe; leurre Adobe Framesync.
Les fichiers JavaScript utilisent des noms en portugais (COMPROVANTE, Extrato, PIX).
Vol de cookies/sessionStorage/localStorage; lecture mémoire via ReadProcessMemory.
The extension can take screenshots of the selected or active tab and upload a compressed image.
After establishing a WebSocket channel with the C2 server, the extension also polls a '/google_api/' endpoint through requests masquerading as CSS file fetches.
The operation leverages Ethereum smart contracts as dead drop resolvers to dynamically update command-and-control endpoints and payload hosting locations.
Récupération de configuration depuis un smart contract Ethereum; résolution C2 dynamique via smart contract.
Téléchargement de Node.js, récupération de configuration, téléchargement des binaires.
86 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brazil-focused banking-malware toolkit delivered through document-themed JavaScript lures. It uses staged loaders, a custom installer, DLL sideloading, Ethereum smart contracts for resilient C2/payload resolution, and a malicious Chromium extension that steals browser credentials, cookies, session and local storage, browsing data, screenshots, page HTML, and intercepted requests.
Brazil-focused banking-malware toolkit/loader that deploys a malicious Chromium extension. It evades sandboxing, establishes persistence, retrieves configuration and payload locations from Ethereum smart contracts, and bypasses Chromium extension protections by modifying Secure Preferences and recovering Chrome cryptographic keys from process memory. The deployed extension steals browser data and enables screen capture, keylogging, HTML injection, HTTP interception, and redirection.
A Brazilian banking-malware toolkit that uses JavaScript loaders, a C++ installer, malicious Chromium extensions, Ethereum smart contracts as dead-drop C2 resolvers, and SentinelOne DLL sideloading. It steals browser credentials, cookies, session tokens, browser storage, page content, screenshots, and keystrokes; it can also inject attacker-controlled HTML and intercept web requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.