Researchers uncovered ParaSiteSnatcher, a malicious browser-extension framework targeting Google Chrome and other Chromium-based browsers to steal and manipulate sensitive data from users in Latin America, with a strong focus on Brazil. The malware monitors tabs, injects malicious scripts, intercepts user input, and captures POST requests before they are transmitted, allowing it to harvest banking and financial information tied to Banco do Brasil and Caixa Econômica Federal. It also steals Brazilian tax ID numbers and cookies, including Microsoft account cookies.
The framework was also built to interfere with Brazilian payment workflows, including PIX transfers and Boleto Bancario transactions, giving attackers a way to alter or abuse online payments. Researchers said the malware is delivered through a VBScript downloader hosted on Dropbox and Google Cloud, and observed three downloader variants that added stronger obfuscation, anti-analysis checks, and randomization. Before installation, the downloader verifies that Google Chrome is present and that the victim has a valid AppData path, indicating a targeted and evolving campaign.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers found that ParaSiteSnatcher is delivered through a VBScript downloader hosted on Dropbox and Google Cloud. They observed three downloader variants with progressively stronger obfuscation and anti-analysis features, including reverse-string obfuscation, junk code, anti-debugging, anti-tamper protections, and randomized names.
Trend Micro researchers identified a malicious browser extension framework named ParaSiteSnatcher that targets Google Chrome and other Chromium-based browsers, with a focus on users in Latin America, especially Brazil. The framework steals and manipulates sensitive data, including banking information, PIX and Boleto payment activity, Brazilian tax IDs, and cookies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.