Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

KREMLIN malware campaign targets Chrome and Edge users

TechRadar reports that Elastic Security Labs has uncovered a Brazilian banking malware campaign that uses browser extensions to steal sensitive information from Chrome and Edge users. The campaign, tracked as REF9334, has been active since at least May 2025, according to the researchers.

Fake banking, invoice, and business documents are used to trick victims into installing the malware. On a real computer, it deploys a malicious browser extension named “AVSync System Inc.” to appear like an antivirus add-on. The malware first checks whether it is running in a sandbox and does not proceed if it detects one.

Rather than relying on a fixed command-and-control server, the campaign stores information on the Ethereum blockchain, which Elastic said makes communication harder to disrupt. During the investigation, researchers took control of a domain used by the malware and found 1,515 infected systems. Almost all, or 98%, were in Brazil.

Elastic also registered the network canary domain and pointed it to its own web host. The loader then treated the environment as a sandbox, meaning “the infections have not moved past the initial access”, the researchers explained. Elastic published a full list of indicators of compromise.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.