home.social

#remcosrat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remcosrat, aggregated by home.social.

  1. The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

    Brazilian banking malware operation REF9334 has been deploying KREMLIN toolkit since May 2025, targeting Brazilian financial institutions through malicious browser extensions. The operation uses multi-stage JavaScript loaders, custom C++ installers, and exploits Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs. Infrastructure leverages Ethereum smart contracts as dead-drop resolvers for dynamic C2 configuration. Seven distinct campaigns over 15 months show evolution from PULSAR RAT to REMCOS RAT delivery. Attackers impersonate twelve Brazilian banks through Portuguese-language lures, with transaction patterns clustering during São Paulo working hours. The malicious extensions intercept credentials, session tokens, and sensitive banking data through keylogging and request interception capabilities. Over 1,500 infections have been temporarily disrupted through network canary registration, with 98.75% of victims located in Brazil.

    Pulse ID: 6aaa6f52c8d835e24adb63f7
    Pulse Link: otx.alienvault.com/pulse/6aaa6
    Pulse Author: AlienVault
    Created: 2026-09-16 10:28:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Brazil #JavaScript #RemcosRAT #OTX #AlienVault